From c03a31cec5895782ef00fcc82f58a0e7eaf1a94e Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 22 Sep 2026 20:01:14 +0200 Subject: [PATCH] Count only a record of making something at a path as the mesh's, not an access record (hq ADR 0103) --- internal/apply/hold.go | 7 +++++-- internal/apply/hold_test.go | 21 +++++++++++++++++++++ 2 files changed, 26 insertions(+), 2 deletions(-) diff --git a/internal/apply/hold.go b/internal/apply/hold.go index fc82f0f..935ec69 100644 --- a/internal/apply/hold.go +++ b/internal/apply/hold.go @@ -189,10 +189,13 @@ func present(path string) bool { return err == nil } -// recordedPath is whether this host has a record of making something at a path. +// recordedPath is whether this host has a record of MAKING something at a path — a directory it +// created, a file it wrote, an archive it unpacked. An access record is not one of those: it says +// the mesh set permissions on a path it does not own, which is exactly what it does to a path +// somebody else's software made, so a path it only has access for is still found (novox/hq ADR 0103). func recordedPath(known store.State, path string) bool { for _, kind := range []declaration.Type{declaration.TypeDirectory, declaration.TypeFile, - declaration.TypeArchive, declaration.TypeAccess} { + declaration.TypeArchive} { if known.Recorded(string(kind), path) { return true } diff --git a/internal/apply/hold_test.go b/internal/apply/hold_test.go index 112f1a7..0651f4f 100644 --- a/internal/apply/hold_test.go +++ b/internal/apply/hold_test.go @@ -1020,3 +1020,24 @@ func TestAHoldLetGoAndFoundAgainKeepsBothOriginals(t *testing.T) { t.Errorf("the file found again was not held: %+v", o) } } + +func TestAPathTheMeshOnlySetAccessOnIsStillFound(t *testing.T) { + // An access record says the mesh set permissions on a path it does not own — which is what it + // does to somebody else's directory. It is not a record of making it (novox/hq ADR 0103). + dir := t.TempDir() + data := filepath.Join(dir, "data") + if err := os.Mkdir(data, 0o700); err != nil { + t.Fatal(err) + } + known := store.State{Resources: []store.Applied{ + {ID: "hello-web.readable", Type: "access", Target: data, Origin: store.OriginDeclared}}} + m := &machine{containers: map[string]*fakeContainer{}} + report, _ := applyAdopted(t, adopted(t, untaken("hello-web.data"), + `{"id":"hello-web.data","type":"directory","path":"`+data+`","mode":"0755"}`), known, m, dir) + if o := outcomeOf(report, "hello-web.data"); o.Action != "held" { + t.Errorf("a directory the mesh only has access for was not held: %+v", o) + } + if info, _ := os.Stat(data); info.Mode().Perm() != 0o700 { + t.Errorf("it was re-moded to %o", info.Mode().Perm()) + } +}