Cite hq ADR 0170, not 0169: the firewall seat's record was renumbered after a collision on hq main

This commit is contained in:
2026-10-02 14:52:20 +02:00
parent a8f1cdb445
commit cdbe3ab0a4
4 changed files with 4 additions and 4 deletions
+1 -1
View File
@@ -1583,7 +1583,7 @@ func containerSpecReading(r *declaration.Container, declares, reads map[string]s
for _, n := range r.Networks { for _, n := range r.Networks {
b.WriteString("also-on " + n + "\n") b.WriteString("also-on " + n + "\n")
} }
// And the capabilities it was granted (ADR 0169): one gained or dropped is a different // And the capabilities it was granted (ADR 0170): one gained or dropped is a different
// container, and the runtime cannot change a running one's. // container, and the runtime cannot change a running one's.
for _, c := range r.Capabilities { for _, c := range r.Capabilities {
b.WriteString("cap " + c + "\n") b.WriteString("cap " + c + "\n")
+1 -1
View File
@@ -135,7 +135,7 @@ func TestALeftOutModuleIsNeitherRemovedNorForgotten(t *testing.T) {
} }
} }
// A container's capabilities reach the runtime and are part of its spec (novox/hq ADR 0169). // A container's capabilities reach the runtime and are part of its spec (novox/hq ADR 0170).
func TestACapabilityReachesTheRuntimeAndTheSpec(t *testing.T) { func TestACapabilityReachesTheRuntimeAndTheSpec(t *testing.T) {
var ran []string var ran []string
run := func(_ context.Context, name string, args ...string) (string, error) { run := func(_ context.Context, name string, args ...string) (string, error) {
+1 -1
View File
@@ -941,7 +941,7 @@ type Container struct {
Dns []string `json:"dns,omitempty"` Dns []string `json:"dns,omitempty"`
// Capabilities are the Linux capabilities this container is granted beyond the runtime's // Capabilities are the Linux capabilities this container is granted beyond the runtime's
// default set, by name (novox/hq ADR 0169): a holder's runtime that changes the machine's packet // default set, by name (novox/hq ADR 0170): a holder's runtime that changes the machine's packet
// filter asks for NET_ADMIN. Exactly these, named in the spec so a change recreates the // filter asks for NET_ADMIN. Exactly these, named in the spec so a change recreates the
// container; a privileged container stays undeclarable. // container; a privileged container stays undeclarable.
Capabilities []string `json:"capabilities,omitempty"` Capabilities []string `json:"capabilities,omitempty"`
+1 -1
View File
@@ -505,7 +505,7 @@ func TestKeptNetworksAndLeftOutModulesAreReadStrictly(t *testing.T) {
} }
} }
// A container may ask for a capability by name, and nothing else (novox/hq ADR 0169). // A container may ask for a capability by name, and nothing else (novox/hq ADR 0170).
func TestACapabilityIsNamedOrRefused(t *testing.T) { func TestACapabilityIsNamedOrRefused(t *testing.T) {
image := "postgres@sha256:" + strings.Repeat("a", 64) image := "postgres@sha256:" + strings.Repeat("a", 64)
d, err := Parse([]byte(`{"declaration":1,"resources":[ d, err := Parse([]byte(`{"declaration":1,"resources":[