docs: volume identity, and volumes.csv as danos's fstab

Decision 8 in the rationale, mirrored into the architecture's volume-manager
section: the mount map keys on CONTENT identity, never port or arrival order
— Linux's /dev/sda1-era fstab broke on every port move until UUID= replaced
it, and danos skips that era. The identity ladder the prober reads off the
medium: GPT partition GUID, filesystem UUID, FAT serial+label, MBR
signature+index, anonymous. Consequences are mechanical: port moves change
nothing (USB, hub, SATA bay, or transport swaps), replug remounts at the
same path, the boot volume is a recorded identity findable anywhere, and
cloned duplicates are a loud policy case instead of silent shadowing.
/volumes/<name> stands as the hierarchy's home for attached media; minting
identifiers (formatting, entropy) stays deliberately out of scope.
This commit is contained in:
Daniel Samson
2026-08-09 15:59:38 +01:00
parent 728b436d0f
commit ada251150a
2 changed files with 43 additions and 3 deletions
@@ -83,9 +83,20 @@ policy), enforced by nobody else:
- `filesystems.csv` — content signature → filesystem binary. Adding a
filesystem adds a row.
- the mount map — volume identity → mount prefix. The boot volume is chosen
by **content** (the volume carrying `/system/configuration` and
`/system/logs`), never by port or arrival order.
- `volumes.csv` — the mount map, danos's fstab: **volume identity → mount
prefix**, keyed on content identity and never on port, path, or arrival
order (the lesson of Linux's `/dev/sda1`-era fstab, which broke on every
port move until `UUID=` replaced it). Identity is read off the medium by
the prober, strongest first: GPT partition GUID → filesystem UUID → FAT
serial + label → MBR signature + partition index → anonymous (generated
name, no persistence). Same identity, same mount point: a drive moved to
another port — USB to another hub, SATA to another bay, even a stick
returning in a different dock — lands exactly where it was. Duplicate
identity (cloned sticks, together) is policy: first keeps the name, the
second mounts suffixed and is logged loudly. The boot volume is the
recorded identity of the volume carrying `/system/configuration` and
`/system/logs`, findable on any port. Unknown volumes mount under
`/volumes/<derived name>`.
**Filesystem service** (the FAT service today; one process per volume): the
proven unit — block-client + engine + file-protocol provider in one binary. It