A filter module's own filter file counts as declared for a mount (hq ADR 0169)

The nftables module's runtime mounts the file filtering.into names, to reload
the mesh's table; the mount check knew every other declaration of a path and
not this one, and the module's first build was refused for it.
This commit is contained in:
2026-10-02 14:04:35 +02:00
parent 30d548a762
commit 9d13b0593b
2 changed files with 16 additions and 0 deletions
+6
View File
@@ -1810,6 +1810,12 @@ func (m Manifest) undeclaredMounts() []string {
claim(p)
}
}
// The file a filter module's rule set is written to is declared by `filtering.into`: the mesh
// writes it, the module loads it, and the module's runtime may read it back to reload the
// mesh's own table (novox/hq ADR 0169).
if m.Filtering != nil {
claim(m.Filtering.Into)
}
// Under a declared directory is declared: a module that says where its data lives has said so
// for what it puts inside.
covers := func(path string) bool {