A module accesses operator-owned data, it does not own it (ADR 0051) #8

Merged
jschoubben merged 1 commits from feat/shared-data-access into main 2026-09-05 20:48:11 +00:00
Owner

Implements ADR 0051. Adds an accesses: [{path, mode}] manifest field, distinct from owned resources (chosen over a flag-on-directory to avoid the issue-026 "two kinds spelled the same" trap). Because an access is not a resource, the resolver's duplicate-path check ignores it — so co-access falls out and the eight-module media stack co-resolves. Enforced: a path one module owns and another accesses is refused (ownership contradiction). Renders as an access declaration resource before the mounting container. Four unit tests (co-resolution = the case issue 036 refused; owner-vs-owner still refused; owner-vs-accessor refused; validation); go test ./... green.

https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF

Implements ADR 0051. Adds an `accesses: [{path, mode}]` manifest field, distinct from owned `resources` (chosen over a flag-on-directory to avoid the issue-026 "two kinds spelled the same" trap). Because an access is not a resource, the resolver's duplicate-path check ignores it — so co-access falls out and the eight-module media stack co-resolves. Enforced: a path one module owns and another accesses is refused (ownership contradiction). Renders as an `access` declaration resource before the mounting container. Four unit tests (co-resolution = the case issue 036 refused; owner-vs-owner still refused; owner-vs-accessor refused; validation); `go test ./...` green. https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben added 1 commit 2026-09-05 20:47:56 +00:00
04-ISSUES/036: the media stack is several modules that must share the
library and download directories on one machine, but the manifest could
only say "a directory I own". Six modules each declared the same paths as
their own resources, and the resolver's duplicate-owner refusal — right
in general — would refuse the stack's only sensible assignment the first
time two of them landed on one node.

Add an `accesses` field: a pre-existing, operator-owned path a module is
granted use of but does not own (novox/hq ADR 0051). Distinct from a
`directory` resource on every axis the host acts on — the mesh creates,
chowns and reconciles a directory; it mounts an access and owns nothing.
An access is not a resource, so it never enters the duplicate-owner map
and several modules may name one path with no conflict. What is refused
is the contradiction: a path one module owns and another accesses.

Rendered into the declaration as an `access` resource, before the
container that mounts it, so the host can find it present or refuse
clearly. Unit tests cover co-resolution (the exact 036 case), the
unchanged owner-vs-owner refusal, the owner-vs-accessor refusal, and
access validation.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben merged commit 6bb9434298 into main 2026-09-05 20:48:11 +00:00
jschoubben deleted branch feat/shared-data-access 2026-09-05 20:48:12 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#8