Skip to main content

Module nodes_apply

Module nodes_apply 

Source
Expand description

Phase 34 — the filesystem half of a node: hash a target, apply bytes to it transactionally, and keep the last few versions.

The rules, in the order they matter:

  1. The bytes must hash to what the hub said they hash to, before anything is touched. Phase 37’s approval token binds to that hash.
  2. The write is temp file in the same directory, fsync, rename. A reader sees the old file or the new one, never half of either.
  3. The previous file is copied aside first and the last KEEP_VERSIONS are kept.
  4. validate runs against the file in place. Failing it restores the previous file and does not reload.
  5. reload runs last. Failing it restores the previous file and does not try again: the service is in a state only the operator can judge.

Commands come from the node’s own config and nowhere else.

Enums§

Applied

Constants§

COMMAND_TIMEOUT
How long validate or reload may run.
KEEP_VERSIONS

Functions§

apply
Applies content to target. See the module comment for the contract.
hash_file
Hash of the file at path: Ok(None) when it does not exist.
kept_versions
The versions kept for a target, oldest first.
scrub
The last three lines of output, each cut to 200 characters, with any line that is also a line of the file being applied replaced. A validator that echoes the offending line of a config would otherwise put a secret into an error that travels to the hub and into its audit log.
sha256_hex