Tests that read ../../../mesh-catalog or ../../../mesh-host gave a verdict that depended on what sat beside the checkout: a stale or dirty sibling failed them on a desktop, and a missing one skipped them unseen. They now read the clone the build seat puts in MESH_CHECK_BESIDE, failing when it is absent there, and elsewhere a copy captured at a named commit. The skip had hidden that the builder test read a module retired by ADR 0190. The systemd reading test no longer counts the machine's own environment.d.
79 lines
1.4 KiB
Plaintext
79 lines
1.4 KiB
Plaintext
{
|
|
"module": "telegram",
|
|
"version": "1",
|
|
"slug": "tgrm",
|
|
"runs-as": "telegram",
|
|
"claims": [
|
|
{
|
|
"name": "channel",
|
|
"scope": "mesh",
|
|
"kind": "telegram",
|
|
"capabilities": [
|
|
"deliver",
|
|
"reaches-away",
|
|
"silent",
|
|
"edit",
|
|
"max-length:4096",
|
|
"choice",
|
|
"verified-sender",
|
|
"exact-render",
|
|
"code-factor"
|
|
]
|
|
},
|
|
{
|
|
"name": "intake",
|
|
"scope": "mesh",
|
|
"kind": "telegram"
|
|
}
|
|
],
|
|
"state": [
|
|
"offset",
|
|
{
|
|
"name": "messages",
|
|
"ttl-seconds": 2592000
|
|
}
|
|
],
|
|
"own-secrets": {
|
|
"broker": "${dir:state}/broker",
|
|
"telegram-token": "${dir:state}/telegram-token"
|
|
},
|
|
"secrets-owner": "telegram",
|
|
"tools": [
|
|
"telegram_status"
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "account",
|
|
"type": "user",
|
|
"name": "telegram",
|
|
"shell": "/usr/bin/nologin",
|
|
"home": "/var/lib/telegram"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"owner": "telegram",
|
|
"place": "."
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "tools",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/telegram",
|
|
"binary": "telegram",
|
|
"loads": [
|
|
"telegram"
|
|
],
|
|
"env": {
|
|
"MESH_TELEGRAM_TOKEN_FILE": "${dir:state}/telegram-token"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|