c0re: chown per-agent state writes to agent uid:gid (#673)

This commit is contained in:
damocles 2026-05-31 00:23:19 +02:00 committed by Mara
commit 0cf703a939
3 changed files with 70 additions and 0 deletions

View file

@ -274,10 +274,25 @@ pub async fn ensure_user_for(
std::fs::write(&path, format!("{access_token}\n"))
.with_context(|| format!("matrix: write token to {}", path.display()))?;
let _ = std::fs::set_permissions(&path, std::fs::Permissions::from_mode(0o600));
chown_to_agent(name, &path);
tracing::info!(%name, path = %path.display(), "matrix: registered user + persisted access token");
Ok(())
}
/// Best-effort chown `path` to the agent's container-local uid/gid.
/// Mirrors `forge::chown_to_agent` for the matrix access-token write —
/// closes the gap where c0re (root on host) writes a file the agent's
/// non-root unix user then can't read until the next activation runs
/// the harness-base.nix chown fixup (#673).
fn chown_to_agent(name: &str, path: &Path) {
let Some((uid, gid)) = crate::lifecycle::agent_uid_gid(name) else {
return;
};
if let Err(e) = std::os::unix::fs::chown(path, Some(uid), Some(gid)) {
tracing::debug!(%name, path = %path.display(), error = %e, "matrix: chown to agent failed");
}
}
/// Register a matrix account for `name` with the supplied `password`
/// and return the freshly-minted access token. Unlike [`ensure_user_for`],
/// the token is **not** persisted to disk — the caller is responsible