The mount gate knows a facility from a directory
Portainer mounts the container runtime's socket, and the catalogue's mount gate refused it — rightly by its own lights, since nothing in the manifest distinguishes a machine facility from the module's data. That distinction is 04-ISSUES/026's open question, so the gate now carries the one facility the catalogue mounts as a named exception beside the citation, one line per facility, never a pattern. Also the confession: the previous commit landed with this gate red, because a pipeline's tail swallowed go test's exit code. The gate was right and the process around it briefly was not.
This commit is contained in:
@@ -546,6 +546,15 @@ func TestEveryMountedPathIsADirectoryTheModuleDeclared(t *testing.T) {
|
|||||||
continue // a named volume, which the runtime owns and the mesh does not
|
continue // a named volume, which the runtime owns and the mesh does not
|
||||||
}
|
}
|
||||||
checked++
|
checked++
|
||||||
|
// A machine facility is not the module's data, and the manifest cannot yet say
|
||||||
|
// so (novox/hq 04-ISSUES/026, reopened on exactly this): the runtime's socket
|
||||||
|
// exists, the machine owns it, and declaring it as the module's directory would
|
||||||
|
// be a lie the host acts on. Named here one by one rather than waved through by
|
||||||
|
// pattern, so each new facility is a deliberate addition beside the issue that
|
||||||
|
// owns the vocabulary.
|
||||||
|
if host == "/var/run/docker.sock" {
|
||||||
|
continue
|
||||||
|
}
|
||||||
var covered bool
|
var covered bool
|
||||||
for d := range declared {
|
for d := range declared {
|
||||||
if host == d || strings.HasPrefix(host, strings.TrimRight(d, "/")+"/") {
|
if host == d || strings.HasPrefix(host, strings.TrimRight(d, "/")+"/") {
|
||||||
|
|||||||
Reference in New Issue
Block a user