review: a retired configuration that comes back is retired again on its first original, and only wg-quick's own file is ever removed (hq ADR 0119)

Put back by hand, it was found afresh and its copy became the hold's original, so a machine that
kept restoring it kept growing copies and lost which one was first. The first original now stays
the record's, content that differs is kept once beside it, and the note says a rollback means
unassigning the private network. Nothing is removed unless it is <wireguard dir>/<iface>.conf,
not a path the mesh writes, and not a link, which would leave the key-bearing target behind.
This commit is contained in:
jochen
2026-09-27 00:55:50 +02:00
parent b462f461c6
commit 50776b8613
4 changed files with 340 additions and 65 deletions
+15 -18
View File
@@ -189,9 +189,21 @@ type Retired struct {
ID string `json:"id"`
Path string `json:"path"`
// Kept is the original as found (novox/hq ADR 0100) — the record of what the predecessor was,
// and a person's way back if one is ever wanted. The mesh never copies it back.
Kept string `json:"kept"`
At time.Time `json:"at"`
// and a person's way back if one is ever wanted. The mesh never copies it back. It is the FIRST
// original, and stays so however often the file comes back: a retirement repeated never moves
// it. Digest is what it holds.
Kept string `json:"kept"`
Digest string `json:"digest,omitempty"`
// Extra is where what was at the path when it was last retired is kept, when that differed from
// the first original — rewritten since it was found, or put back with other content — and
// ExtraDigest what it holds. One copy per distinct content: a file that comes back as it was
// last retired keeps nothing more.
Extra string `json:"extra,omitempty"`
ExtraDigest string `json:"extra_digest,omitempty"`
At time.Time `json:"at"`
// Again is how many times the configuration came back after it was retired, and was retired
// again (novox/hq ADR 0119).
Again int `json:"again,omitempty"`
}
// Modes a node can be in (novox/hq ADR 0100).
@@ -355,21 +367,6 @@ func (s *State) RecordRetired(r Retired) {
s.Retired = append(s.Retired, r)
}
// Unretire forgets a retirement: the configuration is at its path again, put back by a person, and
// is found — and kept — afresh.
func (s *State) Unretire(path string) {
kept := s.Retired[:0]
for _, r := range s.Retired {
if r.Path != path {
kept = append(kept, r)
}
}
s.Retired = kept
if len(s.Retired) == 0 {
s.Retired = nil
}
}
// Find returns what was applied under an identity.
func (s State) Find(id string) (Applied, bool) {
for _, r := range s.Resources {