declaration: an access is mounted, and the host owns nothing about it
The tenth shape (novox/hq ADR 0051). Shared, pre-existing data — a media library, a download spool several modules use — is the operator's, not the mesh's. A `directory` resource is the host's own: it creates it, chowns it, sets its mode and removes it when empty. An access is the opposite on every axis. Add the `access` type to the vocabulary. Its applier confirms the path is present and changes nothing: it does not create, chown, reconcile or set a mode. Absent is refused clearly — the operator must provide it — rather than created, because a bind mount whose source is missing is made as root by the container runtime with the wrong ownership (04-ISSUES/026). Undeclaring an access forgets the record and never touches the path, which is the data loss ADR 0030 prevents, on a directory the mesh never made. Full hosts speak it (it gates a bind mount, which needs the container runtime); the vocabulary guard test records the decision that made it the tenth shape. Unit tests cover present, absent-refused, and undeclared-left-alone. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -256,7 +256,7 @@ func TestTheVocabularyIsTheEightShapesTheMeshNeeds(t *testing.T) {
|
||||
}
|
||||
for _, want := range []Type{
|
||||
TypeDirectory, TypeFile, TypeService, TypePackage, TypeContainer, TypeAction,
|
||||
TypeUser, TypeArchive, TypeNetwork,
|
||||
TypeUser, TypeArchive, TypeNetwork, TypeAccess,
|
||||
} {
|
||||
if !speaks[want] {
|
||||
t.Errorf("the host no longer speaks %q", want)
|
||||
@@ -268,8 +268,12 @@ func TestTheVocabularyIsTheEightShapesTheMeshNeeds(t *testing.T) {
|
||||
// `network` is the ninth, and novox/hq ADR 0029 is the decision that made it one: an action
|
||||
// could create a network and nothing could remove it, because an action leaves no footprint
|
||||
// the host can undo — so the network would outlive every module that was ever unassigned.
|
||||
if len(speaks) != 9 {
|
||||
t.Errorf("the vocabulary is %d shapes rather than 9; every addition widens what a compromised "+
|
||||
//
|
||||
// `access` is the tenth, and novox/hq ADR 0051 is its decision: shared, pre-existing data is
|
||||
// the operator's, and a module is granted use of it without owning it — a shape the host must
|
||||
// tell apart from a directory precisely because it must NOT create, chown or remove it.
|
||||
if len(speaks) != 10 {
|
||||
t.Errorf("the vocabulary is %d shapes rather than 10; every addition widens what a compromised "+
|
||||
"control plane can express, so a change here is a decision: %s",
|
||||
len(speaks), vocabulary())
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user