The virtualisation capability grants the lab its daemon's socket

The lab raises machines on the virtualisation daemon, and a module may
mount a machine's socket only through the capability that grants it
(novox/hq ADR 0172). Also brings the resolver's tests to the setting
dnsmasq's listen addresses now come from, and to a module left out
rather than refused.
This commit is contained in:
2026-10-02 14:46:17 +02:00
parent 252eb786a7
commit a637df01ea
2 changed files with 18 additions and 6 deletions
+2
View File
@@ -1769,6 +1769,8 @@ func (m Manifest) MachineSide(port int) (at int, mayAssign bool) {
var facilitiesOf = map[string][]string{
// Both spellings: /var/run is a link to /run on every machine the mesh runs on.
"container-runtime": {"/var/run/docker.sock", "/run/docker.sock"},
// The virtualisation daemon's socket, for the lab (novox/hq ADR 0172): it raises machines there.
"virtualisation": {"/var/lib/incus/unix.socket"},
}
// undeclaredMounts is every bind-mount source no declaration covers — see the check above.