Implements ADR 0051's host half. Adds a tenth vocabulary shape, access: the applier confirms the path is present (reports no change), refuses clearly if absent ("the operator must provide it… does not own"), and never creates/chowns/reconciles it; removal is forgotten (never touches the path). Updates the two vocabulary-guard tests (9→10, backed by ADR 0051) and adds access to full-host everyShape. Three unit tests (present-confirmed, absent-refused-not-created, undeclared-left-alone); full go test ./... green.
Implements ADR 0051's host half. Adds a tenth vocabulary shape, `access`: the applier confirms the path is present (reports no change), refuses clearly if absent ("the operator must provide it… does not own"), and never creates/chowns/reconciles it; removal is forgotten (never touches the path). Updates the two vocabulary-guard tests (9→10, backed by ADR 0051) and adds `access` to full-host `everyShape`. Three unit tests (present-confirmed, absent-refused-not-created, undeclared-left-alone); full `go test ./...` green.
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
The tenth shape (novox/hq ADR 0051). Shared, pre-existing data — a media
library, a download spool several modules use — is the operator's, not
the mesh's. A `directory` resource is the host's own: it creates it,
chowns it, sets its mode and removes it when empty. An access is the
opposite on every axis.
Add the `access` type to the vocabulary. Its applier confirms the path is
present and changes nothing: it does not create, chown, reconcile or set
a mode. Absent is refused clearly — the operator must provide it — rather
than created, because a bind mount whose source is missing is made as
root by the container runtime with the wrong ownership (04-ISSUES/026).
Undeclaring an access forgets the record and never touches the path,
which is the data loss ADR 0030 prevents, on a directory the mesh never
made.
Full hosts speak it (it gates a bind mount, which needs the container
runtime); the vocabulary guard test records the decision that made it the
tenth shape. Unit tests cover present, absent-refused, and
undeclared-left-alone.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements ADR 0051's host half. Adds a tenth vocabulary shape,
access: the applier confirms the path is present (reports no change), refuses clearly if absent ("the operator must provide it… does not own"), and never creates/chowns/reconciles it; removal is forgotten (never touches the path). Updates the two vocabulary-guard tests (9→10, backed by ADR 0051) and addsaccessto full-hosteveryShape. Three unit tests (present-confirmed, absent-refused-not-created, undeclared-left-alone); fullgo test ./...green.https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF