The host applies the newest declaration, a file may be created once, the foundation filters first

031: a window of unacknowledged declarations is drained to the newest; the
rest are set aside and reported as superseded. 035: a file resource may say
create-once — written when absent, kept untouched when present (ADR 0087).
054: the bundle installs nftables and loads a base ruleset before the store
and broker, in the table the filter module later replaces (ADR 0088).
This commit is contained in:
2026-09-21 12:11:52 +02:00
parent d7eea1ab66
commit b72b71a989
8 changed files with 258 additions and 4 deletions
+12
View File
@@ -470,6 +470,18 @@ func applyFile(r *declaration.File, previous store.Applied, unseal Unseal) (Outc
if readErr != nil && !errors.Is(readErr, os.ErrNotExist) {
return out, readErr
}
// A seed that is already there is left exactly as it is — whatever has grown in it since is
// not the mesh's to put back (novox/hq issue 035). What this host records is what it once
// wrote, so a later declaration that changes the seed is not mistaken for drift either.
if r.CreateOnce && existed {
out.wrote = previous.Wrote
if out.wrote == "" {
out.wrote = digestOf(string(existing))
}
out.Action = "kept"
out.Detail = "created once, and present; what is in it now is not the mesh's to change"
return out, nil
}
var beforeMode os.FileMode
if existed {