Hold a found directory, a found service's unit, a container that would mount found data, and a step run in a held container on an adopted node (hq ADR 0103)

This commit is contained in:
2026-09-22 18:14:37 +02:00
parent 35ecf68393
commit 824cb60cbb
6 changed files with 562 additions and 119 deletions
+21 -29
View File
@@ -161,6 +161,10 @@ func ApplyKeeping(
return report, known, &Error{Resource: "the firewall found on this machine", Err: err, Done: report}
}
// What an adopted node's untaken modules find on the machine, looked at before anything in
// this apply — a removal included — could change it or its records (novox/hq ADR 0103).
before := lookBefore(ctx, sys, d, known, run)
removeOrphan := func(orphan store.Applied) error {
var action, detail string
var err error
@@ -236,36 +240,24 @@ func ApplyKeeping(
var failures []*Error
for _, resource := range d.Resources {
// **On an adopted node, what is found is kept until its module is taken** (novox/hq ADR
// 0100). Before anything is applied: a file present with no record of this host writing
// it, or a container present under that name that no host made, is held as it is and
// reported. Once held it stays held — changed or gone — until its module is taken, and
// it is never recorded as applied, so it is never removed as an orphan either.
if d.Adoption != nil && holdable(resource) {
if module, untaken := d.Adoption.UntakenModuleOf(resource.Identity()); untaken {
was, already := known.HeldAt(resource.Identity())
isFound := false
if !already {
var err error
if isFound, err = found(ctx, resource, run, known); err != nil {
failures = append(failures, &Error{Resource: resource.Identity(), Err: err, Done: report})
log(fmt.Sprintf(" failed %s (%s): %v", resource.Identity(), resource.Target(), err))
continue
}
}
if already || isFound {
outcome, held, err := hold(ctx, resource, module, was, already, run, keep, time.Now().UTC())
if err != nil {
failures = append(failures, &Error{Resource: resource.Identity(), Err: err, Done: report})
log(fmt.Sprintf(" failed %s (%s): %v", resource.Identity(), outcome.Target, err))
continue
}
known.RecordHeld(held)
report.Outcomes = append(report.Outcomes, outcome)
if !already || held.Changed != was.Changed {
log(fmt.Sprintf(" held %s (%s): %s", outcome.ID, outcome.Target, outcome.Detail))
}
continue
// 0100, ADR 0103). Before anything is applied: whatever of a module not yet taken is
// present with no record of this host making it — or would reach what is — is held as it
// is and reported. Once held it stays held until its module is taken, and it is never
// recorded as applied, so it is never removed as an orphan either.
if d.Adoption != nil {
isHeld, news, outcome, err := holdOnAdopted(ctx, sys, resource, d, &known, before, run, keep,
changed, time.Now().UTC())
if err != nil {
failures = append(failures, &Error{Resource: resource.Identity(), Err: err, Done: report})
log(fmt.Sprintf(" failed %s (%s): %v", resource.Identity(), resource.Target(), err))
continue
}
if isHeld {
report.Outcomes = append(report.Outcomes, outcome)
if news {
log(fmt.Sprintf(" held %s (%s): %s", outcome.ID, outcome.Target, outcome.Detail))
}
continue
}
}