Repoint ADR references after HQ consolidated 65 records to 23
96 comments across the two repos named records that no longer exist. Each now points at the consolidated record that holds its reasoning -- ADR 0034 (a test defends a decision) is 0017, the eight host records are 0005, the four lab records are 0016. Worth noting for next time: these are references from outside HQ, so renumbering there is not free. It cost 38 files here.
This commit is contained in:
@@ -3,7 +3,7 @@
|
||||
// Data, never instructions. The vocabulary is finite, versioned, and anything outside it
|
||||
// refuses the whole declaration rather than being skipped — a host that applied most of what
|
||||
// it was sent and reported success is a node that looks configured and is not
|
||||
// (novox/hq ADR 0043).
|
||||
// (novox/hq ADR 0005).
|
||||
package declaration
|
||||
|
||||
import (
|
||||
@@ -162,7 +162,7 @@ type Container struct {
|
||||
ID string `json:"id"`
|
||||
Type Type `json:"type"`
|
||||
Name string `json:"name"`
|
||||
// Image is pinned by digest (novox/hq ADR 0046) — a tag moves and a digest does not.
|
||||
// Image is pinned by digest (novox/hq ADR 0006) — a tag moves and a digest does not.
|
||||
Image string `json:"image"`
|
||||
Env map[string]string `json:"env,omitempty"`
|
||||
Ports []string `json:"ports,omitempty"`
|
||||
@@ -189,7 +189,7 @@ type Action struct {
|
||||
Command []string `json:"command"`
|
||||
// Verify is not optional and is not a courtesy. It is the read-back AND the idempotency
|
||||
// check: the host does not know what a database is, so "is it already there" is a question
|
||||
// only the declaration can ask (novox/hq ADR 0047).
|
||||
// only the declaration can ask (novox/hq ADR 0005).
|
||||
Verify []string `json:"verify"`
|
||||
// In names a container to run inside. Empty means the machine itself.
|
||||
In string `json:"in,omitempty"`
|
||||
@@ -207,7 +207,7 @@ func (a *Action) Target() string {
|
||||
}
|
||||
|
||||
func (a *Action) validate(where string, allowActions bool) []string {
|
||||
// The bound the whole security argument rests on (novox/hq ADR 0047).
|
||||
// The bound the whole security argument rests on (novox/hq ADR 0005).
|
||||
if !allowActions {
|
||||
return []string{where +
|
||||
": an action arrived over the link, and the link may not carry one. The host " +
|
||||
@@ -264,7 +264,7 @@ type Declaration struct {
|
||||
// nothing to check against.
|
||||
For string
|
||||
// Resources, in the order they are applied. The host does not sort them: ordering is a
|
||||
// decision, and deciding is not what the host does (novox/hq ADR 0037).
|
||||
// decision, and deciding is not what the host does (novox/hq ADR 0005).
|
||||
Resources []Resource
|
||||
}
|
||||
|
||||
@@ -286,14 +286,14 @@ func (e *RefusalError) Error() string {
|
||||
}
|
||||
|
||||
// Parse reads a declaration that arrived over the link, and refuses anything it does not fully
|
||||
// understand — including any action, which the link may not carry (novox/hq ADR 0047).
|
||||
// understand — including any action, which the link may not carry (novox/hq ADR 0005).
|
||||
func Parse(raw []byte) (*Declaration, error) { return parse(raw, false) }
|
||||
|
||||
// ParseTrusted reads a declaration from a source already as privileged as the host itself: the
|
||||
// bundle it carries, or a file handed to it by someone who is running it as root.
|
||||
//
|
||||
// Actions are permitted here and nowhere else. The asymmetry is deliberate and is the entire
|
||||
// content of ADR 0047: refusing actions from the bundle buys nothing, because whoever built the
|
||||
// content of ADR 0005: refusing actions from the bundle buys nothing, because whoever built the
|
||||
// bundle built the binary; refusing them from the link buys the bound on what a compromised
|
||||
// control plane can express.
|
||||
func ParseTrusted(raw []byte) (*Declaration, error) { return parse(raw, true) }
|
||||
@@ -450,7 +450,7 @@ func checkMode(where, mode string) []string {
|
||||
// checkImage insists on a digest.
|
||||
//
|
||||
// A tag moves and a digest does not. The bundle's whole claim is that what it names is exact
|
||||
// (novox/hq ADR 0046), and a bundle pinning `postgres:17` pins nothing — it names whatever
|
||||
// (novox/hq ADR 0006), and a bundle pinning `postgres:17` pins nothing — it names whatever
|
||||
// that tag points at on the day the host happens to run.
|
||||
func checkImage(where, image string) []string {
|
||||
if image == "" {
|
||||
|
||||
@@ -6,7 +6,7 @@ import (
|
||||
"testing"
|
||||
)
|
||||
|
||||
// Each test names the decision it defends (novox/hq ADR 0034). The decision here is ADR 0043,
|
||||
// Each test names the decision it defends (novox/hq ADR 0017). The decision here is ADR 0005,
|
||||
// and the property it turns on is that unknown is REFUSED, never skipped.
|
||||
|
||||
func valid() string {
|
||||
@@ -160,7 +160,7 @@ func TestAnEmptyDeclarationIsAMistake(t *testing.T) {
|
||||
// --- the vocabulary the substrate bootstrap needs (novox/hq 07-the-substrate.md) ---
|
||||
|
||||
func TestAnActionOverTheLinkIsRefused(t *testing.T) {
|
||||
// novox/hq ADR 0047. The link may push declarations of known shape and never a command to
|
||||
// novox/hq ADR 0005. The link may push declarations of known shape and never a command to
|
||||
// run. This is the boundary the whole security argument rests on, so it is asserted
|
||||
// directly rather than inferred from the type list.
|
||||
raw := []byte(`{"declaration":1,"resources":[
|
||||
@@ -195,7 +195,7 @@ func TestAnActionWithoutVerifyIsRefused(t *testing.T) {
|
||||
}
|
||||
|
||||
func TestAnImageMustBePinnedByDigest(t *testing.T) {
|
||||
// novox/hq ADR 0046: reproducibility comes from pinning the identity of a thing. A bundle
|
||||
// novox/hq ADR 0006: reproducibility comes from pinning the identity of a thing. A bundle
|
||||
// naming a tag pins nothing — it names whatever that tag points at on the day it runs.
|
||||
for _, image := range []string{
|
||||
"postgres:17",
|
||||
|
||||
Reference in New Issue
Block a user