Refuse an action where it was written, not on the machine
A module may not declare an action: the link may not carry a command to run, and that bound is what limits a compromised control plane to shapes it cannot turn into arbitrary code (novox/hq ADR 0005). The host enforces it, correctly and in the right place. But a module's resources reach a machine over the link, so a manifest carrying an action was accepted here, stored, resolved, planned and pushed — and refused on the machine, in the host's log, with nothing connecting it back to the manifest that caused it. The rule held. It was just unusable, which is the same shape as the network shape earlier today: the refusal was right, arrived far from its cause, and nobody was reading the log. The refusal names the rule and what to do instead, because "you may not" with no alternative is where a module author stops. Found while checking a claim I had written in the coverage document — that a module cannot declare one. It could; it just could not deliver it. The document is corrected.
This commit is contained in:
@@ -573,6 +573,28 @@ func ParseManifest(raw []byte) (Manifest, error) {
|
||||
m.Module, c.Authority))
|
||||
}
|
||||
}
|
||||
// **A module may not declare an action, and this is where it is said** (novox/hq ADR 0005).
|
||||
//
|
||||
// The host already refuses one, correctly and for the right reason: the link may not carry a
|
||||
// command to run, and that bound is what limits a compromised control plane to shapes it
|
||||
// cannot turn into arbitrary code. But a module's resources reach a machine over the link, so
|
||||
// a manifest carrying an action was accepted here, stored, resolved, planned and pushed — and
|
||||
// refused on the machine, in the host's log, with nothing connecting it back to the manifest
|
||||
// that caused it.
|
||||
//
|
||||
// That is the same failure as the network shape earlier today: the refusal was right, arrived
|
||||
// far from its cause, and nobody was reading the log. A rule enforced only at the far end is
|
||||
// enforced; it is just not usable.
|
||||
for _, r := range m.Resources {
|
||||
if fmt.Sprint(r["type"]) != "action" {
|
||||
continue
|
||||
}
|
||||
problems = append(problems, fmt.Sprintf(
|
||||
"%s declares %v, which is an action, and a module may not: the link may not carry a "+
|
||||
"command to run (novox/hq ADR 0005). A module that needs something done ships a "+
|
||||
"program that reads what the mesh delivered and reconciles",
|
||||
m.Module, r["id"]))
|
||||
}
|
||||
for name, where := range m.OwnSecrets {
|
||||
if !strings.HasPrefix(where, "/") {
|
||||
problems = append(problems, fmt.Sprintf(
|
||||
|
||||
Reference in New Issue
Block a user