Expand description
Phase 34 — the filesystem half of a node: hash a target, apply bytes to it transactionally, and keep the last few versions.
The rules, in the order they matter:
- The bytes must hash to what the hub said they hash to, before anything is touched. Phase 37’s approval token binds to that hash.
- The write is temp file in the same directory,
fsync, rename. A reader sees the old file or the new one, never half of either. - The previous file is copied aside first and the last
KEEP_VERSIONSare kept. validateruns against the file in place. Failing it restores the previous file and does not reload.reloadruns last. Failing it restores the previous file and does not try again: the service is in a state only the operator can judge.
Commands come from the node’s own config and nowhere else.
Enums§
Constants§
- COMMAND_
TIMEOUT - How long
validateorreloadmay run. - KEEP_
VERSIONS
Functions§
- apply
- Applies
contenttotarget. See the module comment for the contract. - hash_
file - Hash of the file at
path:Ok(None)when it does not exist. - kept_
versions - The versions kept for a target, oldest first.
- scrub
- The last three lines of
output, each cut to 200 characters, with any line that is also a line of the file being applied replaced. A validator that echoes the offending line of a config would otherwise put a secret into an error that travels to the hub and into its audit log. - sha256_
hex