The mount gate knows a facility from a directory

Portainer mounts the container runtime's socket, and the catalogue's
mount gate refused it — rightly by its own lights, since nothing in the
manifest distinguishes a machine facility from the module's data. That
distinction is 04-ISSUES/026's open question, so the gate now carries
the one facility the catalogue mounts as a named exception beside the
citation, one line per facility, never a pattern.

Also the confession: the previous commit landed with this gate red,
because a pipeline's tail swallowed go test's exit code. The gate was
right and the process around it briefly was not.
This commit is contained in:
2026-09-02 02:09:10 +02:00
parent d278edabe0
commit 68a9235792
+9
View File
@@ -546,6 +546,15 @@ func TestEveryMountedPathIsADirectoryTheModuleDeclared(t *testing.T) {
continue // a named volume, which the runtime owns and the mesh does not
}
checked++
// A machine facility is not the module's data, and the manifest cannot yet say
// so (novox/hq 04-ISSUES/026, reopened on exactly this): the runtime's socket
// exists, the machine owns it, and declaring it as the module's directory would
// be a lie the host acts on. Named here one by one rather than waved through by
// pattern, so each new facility is a deliberate addition beside the issue that
// owns the vocabulary.
if host == "/var/run/docker.sock" {
continue
}
var covered bool
for d := range declared {
if host == d || strings.HasPrefix(host, strings.TrimRight(d, "/")+"/") {