diff --git a/docs/storage-stack-plan.md b/docs/storage-stack-plan.md index 9851683..e7c1712 100644 --- a/docs/storage-stack-plan.md +++ b/docs/storage-stack-plan.md @@ -35,7 +35,8 @@ S5 removal robustness ── independent; single-volume ── may land any time comes FIRST because a volume's mount name is now its identity (below), and the friendly form of that name is the FAT label / GPT name S1 parses. - **S2** moves the last policy out of hardcode into `volumes.csv` + - `filesystems.csv`, and names each volume by its identity — no port-name. + `filesystems.csv`, and names each volume by its identity **id** (a GUID/key), + keeping the label as separate, queryable display metadata — no port-name. - **S3** generalizes to N volumes across N devices. - **S4** adds exFAT — a COMPLETE second engine that proves the V1 harness extraction. Needs S2 (to route by signature) and S3 (to run a second volume). @@ -52,7 +53,10 @@ rung-4 identity into a ladder that reads the richest available content identity: GPT partition GUID (rung 1, 128-bit), FAT volume serial + label (rung 3), MBR signature + index (rung 4, kept), bare-FAT (kept, enriched to its serial). The `u64` identity becomes a small tagged struct `Identity{ rung, key: u128, label, -has_label }`. Because GPT metadata is at LBA 1 and the entry array beyond it, and +has_label }` — `key` is the **id** (the path handle), `label` is the **display +name** (the GPT 36-char partition name, or the FAT volume label), a separate +field per the id/name split S2 relies on. Because GPT metadata is at LBA 1 and +the entry array beyond it, and the FAT serial is in each partition's VBR, `firstVolume` stops taking one preloaded block-0 slice and takes a `SectorReader` (context + read-one-sector fn, mirroring the engine's `BlockDevice` vtable) — host-testable against a @@ -97,20 +101,36 @@ never drift onto magic constants). ## S2 — the mount map: volumes.csv + filesystems.csv **Goal.** Move the last two pieces of storage policy out of hardcode into -configuration read by the volume manager. `filesystems.csv` (content signature → -filesystem binary) so the VM picks the binary from the probed signature; -`volumes.csv` (identity → mount prefix, danos's fstab) as the explicit override -for a volume the user wants at a fixed path. **The default mount name is the -volume's own identity, never a port or role name**: `/volumes/