Hold a unit an administrator installed whatever its state, and a packaged unit only when the machine uses it (hq ADR 0103)

This commit is contained in:
2026-09-22 19:52:37 +02:00
parent d3f2595968
commit 40e8ea9fda
3 changed files with 103 additions and 5 deletions
+32 -4
View File
@@ -105,14 +105,28 @@ func lookBefore(ctx context.Context, sys system.System, d *declaration.Declarati
if known.Recorded(string(declaration.TypeService), res.Unit) {
continue
}
// Found is what the machine runs: a unit that is running or starts at boot. A unit
// file a package merely ships — a template instance nothing ever started, say the
// private network's own wg-quick@mesh0 — is not a predecessor's service, and holding
// it kept the private network from ever coming up (found by the adoption bed).
// **Found is a unit somebody put on this machine, or one the machine uses.**
//
// Where it comes from first: a unit the service manager loads from outside /usr —
// /etc/systemd/system or /run/systemd/system — was installed by an administrator, so
// it is a predecessor's whatever state it is in, and one deliberately stopped and
// disabled must stay that way (novox/hq ADR 0103).
//
// A unit a package ships, under /usr, is not held by its mere presence: the private
// network's own wg-quick@mesh0 is an instance of a template the tunnel package ships,
// nothing had ever run it, and holding it kept the private network from ever coming up
// (found by the adoption bed). Such a unit is held only if the machine actually uses
// it — running, or started at boot.
state, err := sys.ServiceState(ctx, run, res.Unit)
if err != nil {
continue
}
if from, ok := sys.(unitFiles); ok {
if path, err := from.ServiceUnitFile(ctx, run, res.Unit); err == nil && installedByHand(path) {
seen.is["unit:"+res.Unit] = true
continue
}
}
boot, _ := sys.ServiceBoot(ctx, run, res.Unit)
if state == "running" || boot == "enabled" {
seen.is["unit:"+res.Unit] = true
@@ -150,6 +164,20 @@ func lookBefore(ctx context.Context, sys system.System, d *declaration.Declarati
return seen
}
// unitFiles is a service manager that can say where it loads a unit from.
type unitFiles interface {
ServiceUnitFile(ctx context.Context, run Runner, unit string) (string, error)
}
// installedByHand is whether a unit file is one somebody put on this machine rather than one a
// package ships: anywhere but /usr, where distributions keep what they install.
func installedByHand(path string) bool {
if path == "" {
return false
}
return !strings.HasPrefix(filepath.Clean(path), "/usr/")
}
func present(path string) bool {
_, err := os.Lstat(path)
return err == nil