Slice two of ADR 0112, closing the operator's observation that /var/lib must not appear in a module at all:
place: "." on a pathless directory = the assignment's one directory, <root>/<module> (to-be 27's shape); place never reaches the strictly-parsing host.
The path maps (binds, secrets, own-secrets, receives, grants, secrets-many) fill against placed directories at composition — fresh maps, fresh module slice, because one resolution composes for many nodes.
The five absolute-path checks on those maps accept a placed reference; certificate/operator-keeps/accesses stay absolute-only.
unknownDirRefs scans the maps and validates place itself.
Found by the foundation tests validating the sibling catalogue: #101's blanket replace turned /var/lib/gitea/database.json into ${dir:data}base.json — which resolves correctly by pure string concatenation. The catalogue cleanup that follows this spells it ${dir:state}/database.json. Four new tests; full suite green.
Slice two of ADR 0112, closing the operator's observation that `/var/lib` must not appear in a module at all:
- `place: "."` on a pathless directory = the assignment's one directory, `<root>/<module>` (to-be 27's shape); `place` never reaches the strictly-parsing host.
- The path maps (binds, secrets, own-secrets, receives, grants, secrets-many) fill against placed directories at composition — fresh maps, fresh module slice, because one resolution composes for many nodes.
- The five absolute-path checks on those maps accept a placed reference; certificate/operator-keeps/accesses stay absolute-only.
- `unknownDirRefs` scans the maps and validates `place` itself.
Found by the foundation tests validating the sibling catalogue: #101's blanket replace turned `/var/lib/gitea/database.json` into `${dir:data}base.json` — which resolves correctly by pure string concatenation. The catalogue cleanup that follows this spells it `${dir:state}/database.json`. Four new tests; full suite green.
Slice two of ADR 0112. A pathless directory saying place "." is the
assignment's one directory, <root>/<module> — to-be 27's shape — and
place never reaches the host, which parses strictly. The maps naming
where bindings, credentials and contributions land (binds, secrets,
own-secrets, receives, grants) fill against the placed directories at
composition, into fresh maps and a fresh module slice, because one
resolution composes for many nodes. The five absolute-path checks on
those maps accept a placed reference — resolution makes it absolute
before anything reads it — while certificate, operator-keeps and
accesses paths stay absolute-only: those are the operator's or another
vocabulary's. unknownDirRefs scans the maps too, and validates place
itself: only on a directory, only ".", never beside a stated path.
Found by the foundation tests validating the sibling catalogue: the
first conversion's blanket replace turned /var/lib/gitea/database.json
into ${dir:data}base.json — which resolves to the right path by pure
string concatenation. Production was saved by a coincidence; the
catalogue cleanup that follows spells it ${dir:state}/database.json.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Slice two of ADR 0112, closing the operator's observation that
/var/libmust not appear in a module at all:place: "."on a pathless directory = the assignment's one directory,<root>/<module>(to-be 27's shape);placenever reaches the strictly-parsing host.unknownDirRefsscans the maps and validatesplaceitself.Found by the foundation tests validating the sibling catalogue: #101's blanket replace turned
/var/lib/gitea/database.jsoninto${dir:data}base.json— which resolves correctly by pure string concatenation. The catalogue cleanup that follows this spells it${dir:state}/database.json. Four new tests; full suite green.Slice two of ADR 0112. A pathless directory saying place "." is the assignment's one directory, <root>/<module> — to-be 27's shape — and place never reaches the host, which parses strictly. The maps naming where bindings, credentials and contributions land (binds, secrets, own-secrets, receives, grants) fill against the placed directories at composition, into fresh maps and a fresh module slice, because one resolution composes for many nodes. The five absolute-path checks on those maps accept a placed reference — resolution makes it absolute before anything reads it — while certificate, operator-keeps and accesses paths stay absolute-only: those are the operator's or another vocabulary's. unknownDirRefs scans the maps too, and validates place itself: only on a directory, only ".", never beside a stated path. Found by the foundation tests validating the sibling catalogue: the first conversion's blanket replace turned /var/lib/gitea/database.json into ${dir:data}base.json — which resolves to the right path by pure string concatenation. Production was saved by a coincidence; the catalogue cleanup that follows spells it ${dir:state}/database.json.