build.artifacts[].env on a bundle: words and values with ${dir:…} and ${port:…} only. Refused when a value carries any other reference (a secret's content, a binding), when a word is one the runtime sets for itself, and on any artifact that is not a bundle.
Composed per machine like a container's environment and handed to the runtime as MESH_TOOL_ENV ({"<module>": {"<word>": "<value>"}}), in the unit, so a change to any module's words restarts it. Two bundles of one module disagreeing on a word is refused.
Every file and directory of the module a word names, or that holds one, is owned by the account the runtime runs as, where it says no owner. The tool containers ran as root; node-tools runs as the operator account, and a root-owned 0600 secret or 0700 directory is one it cannot read. Nothing changes on a machine with no account.
Tests: words resolved to this machine's paths and ports; only the named files and directories re-owned; no re-owning without an account; a change to the words changes the process; refusals for ${secret:…}, ${bound:…}, a runtime word, env on an image. The ownership test fails with the pass switched off. Full suite passes from the worktree beside the current catalogue.
No module declares env yet, so declarations are unchanged until the first converted module lands. (Note: ~/projects/novox/mesh-catalog, the reference clone beside the main controller checkout, is stale; its fail2ban predates the claim's verbs and fails the catalogue check there.)
hq ADR 0192, design 38 WP4b.
- `build.artifacts[].env` on a bundle: words and values with `${dir:…}` and `${port:…}` only. Refused when a value carries any other reference (a secret's content, a binding), when a word is one the runtime sets for itself, and on any artifact that is not a bundle.
- Composed per machine like a container's environment and handed to the runtime as `MESH_TOOL_ENV` (`{"<module>": {"<word>": "<value>"}}`), in the unit, so a change to any module's words restarts it. Two bundles of one module disagreeing on a word is refused.
- Every file and directory of the module a word names, or that holds one, is owned by the account the runtime runs as, where it says no owner. The tool containers ran as root; node-tools runs as the operator account, and a root-owned 0600 secret or 0700 directory is one it cannot read. Nothing changes on a machine with no account.
Tests: words resolved to this machine's paths and ports; only the named files and directories re-owned; no re-owning without an account; a change to the words changes the process; refusals for `${secret:…}`, `${bound:…}`, a runtime word, `env` on an image. The ownership test fails with the pass switched off. Full suite passes from the worktree beside the current catalogue.
No module declares `env` yet, so declarations are unchanged until the first converted module lands. (Note: `~/projects/novox/mesh-catalog`, the reference clone beside the main controller checkout, is stale; its fail2ban predates the claim's verbs and fails the catalogue check there.)
build.artifacts[].env on a bundle: words and values written with ${dir:…} and ${port:…} only,
refused when a value carries any other reference (a secret's content, a binding) or names a word
the runtime sets for itself, and on any artifact that is not a bundle. Resolved per machine like a
container's environment and handed to the runtime as MESH_TOOL_ENV, module by module, in the unit
so a change restarts it. Every file and directory of the module a word names, or that holds one, is
owned by the account the runtime runs as where it says no owner, since a tool reads as that account.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
hq ADR 0192, design 38 WP4b.
build.artifacts[].envon a bundle: words and values with${dir:…}and${port:…}only. Refused when a value carries any other reference (a secret's content, a binding), when a word is one the runtime sets for itself, and on any artifact that is not a bundle.MESH_TOOL_ENV({"<module>": {"<word>": "<value>"}}), in the unit, so a change to any module's words restarts it. Two bundles of one module disagreeing on a word is refused.Tests: words resolved to this machine's paths and ports; only the named files and directories re-owned; no re-owning without an account; a change to the words changes the process; refusals for
${secret:…},${bound:…}, a runtime word,envon an image. The ownership test fails with the pass switched off. Full suite passes from the worktree beside the current catalogue.No module declares
envyet, so declarations are unchanged until the first converted module lands. (Note:~/projects/novox/mesh-catalog, the reference clone beside the main controller checkout, is stale; its fail2ban predates the claim's verbs and fails the catalogue check there.)build.artifacts[].env on a bundle: words and values written with ${dir:…} and ${port:…} only, refused when a value carries any other reference (a secret's content, a binding) or names a word the runtime sets for itself, and on any artifact that is not a bundle. Resolved per machine like a container's environment and handed to the runtime as MESH_TOOL_ENV, module by module, in the unit so a change restarts it. Every file and directory of the module a word names, or that holds one, is owned by the account the runtime runs as where it says no owner, since a tool reads as that account.