From cdbe3ab0a4328ea8f7027afeeef1877f19d5fce0 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 2 Oct 2026 14:52:20 +0200 Subject: [PATCH] Cite hq ADR 0170, not 0169: the firewall seat's record was renumbered after a collision on hq main --- internal/apply/apply.go | 2 +- internal/apply/left_out_test.go | 2 +- internal/declaration/declaration.go | 2 +- internal/declaration/declaration_test.go | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/internal/apply/apply.go b/internal/apply/apply.go index a64123c..d5b1e55 100644 --- a/internal/apply/apply.go +++ b/internal/apply/apply.go @@ -1583,7 +1583,7 @@ func containerSpecReading(r *declaration.Container, declares, reads map[string]s for _, n := range r.Networks { b.WriteString("also-on " + n + "\n") } - // And the capabilities it was granted (ADR 0169): one gained or dropped is a different + // And the capabilities it was granted (ADR 0170): one gained or dropped is a different // container, and the runtime cannot change a running one's. for _, c := range r.Capabilities { b.WriteString("cap " + c + "\n") diff --git a/internal/apply/left_out_test.go b/internal/apply/left_out_test.go index a4d2d5c..de19496 100644 --- a/internal/apply/left_out_test.go +++ b/internal/apply/left_out_test.go @@ -135,7 +135,7 @@ func TestALeftOutModuleIsNeitherRemovedNorForgotten(t *testing.T) { } } -// A container's capabilities reach the runtime and are part of its spec (novox/hq ADR 0169). +// A container's capabilities reach the runtime and are part of its spec (novox/hq ADR 0170). func TestACapabilityReachesTheRuntimeAndTheSpec(t *testing.T) { var ran []string run := func(_ context.Context, name string, args ...string) (string, error) { diff --git a/internal/declaration/declaration.go b/internal/declaration/declaration.go index ec02074..c7419b4 100644 --- a/internal/declaration/declaration.go +++ b/internal/declaration/declaration.go @@ -941,7 +941,7 @@ type Container struct { Dns []string `json:"dns,omitempty"` // Capabilities are the Linux capabilities this container is granted beyond the runtime's - // default set, by name (novox/hq ADR 0169): a holder's runtime that changes the machine's packet + // default set, by name (novox/hq ADR 0170): a holder's runtime that changes the machine's packet // filter asks for NET_ADMIN. Exactly these, named in the spec so a change recreates the // container; a privileged container stays undeclarable. Capabilities []string `json:"capabilities,omitempty"` diff --git a/internal/declaration/declaration_test.go b/internal/declaration/declaration_test.go index 12e5a54..00fcb62 100644 --- a/internal/declaration/declaration_test.go +++ b/internal/declaration/declaration_test.go @@ -505,7 +505,7 @@ func TestKeptNetworksAndLeftOutModulesAreReadStrictly(t *testing.T) { } } -// A container may ask for a capability by name, and nothing else (novox/hq ADR 0169). +// A container may ask for a capability by name, and nothing else (novox/hq ADR 0170). func TestACapabilityIsNamedOrRefused(t *testing.T) { image := "postgres@sha256:" + strings.Repeat("a", 64) d, err := Parse([]byte(`{"declaration":1,"resources":[