swarm: put the matrix registration token where the reader is granted
`swarm-bao-matrix-token` reads `secret/swarm/matrix/registration-token` and is refused with `Code: 403 — permission denied`, measured on this host at 16:17:49Z after a successful cert login. path.rs makes every swarm path `swarm/<kind>/<name>/…` where Kind is a closed set of four: agents, hives, services, controller. `matrix` sits where a kind belongs, so policy.rs's read document — which emits exactly `swarm/agents/*` and `swarm/hives/<hive>/*` — cannot cover it. The module's own doc predicted this: "a misspelled kind is a 403 at provision time rather than anything a compiler sees". Moves the token to `swarm/hives/<hive>/matrix/registration-token`, built through principal_prefix(Kind::Hive, …) like its per-hive sibling queue::agent_client_path. The policy is untouched: render already grants that prefix. mara chose this over widening the namespace. The nix reader interpolates hyperhiveCfg.hiveName, with the no-fallback reasoning glue-bao-tls.nix already gives at its own use of it. path.rs's MOUNT doc justified itself by citing the old literal, which this commit deletes; rewritten to cite the nix reader instead. Scope: this makes the read reachable, not the value present. Nothing writes that path yet, and a 403 says nothing about presence — the two are separate findings and only the first is fixed here. No migration: nothing ever wrote the old path and no read ever succeeded. Gate: cargo fmt 0, cargo test -p swarm-secret-client 0 — 32 passed against a 29-passed baseline with the change stashed, so the three new tests are accounted for rather than assumed. Refs #4308
This commit is contained in:
parent
2a02c76ad5
commit
14305255f0
4 changed files with 70 additions and 4 deletions
|
|
@ -1148,6 +1148,22 @@ let
|
|||
&& lib.hasInfix "exit 1" loginBranch
|
||||
&& lib.hasInfix "exit 0" (lib.last (lib.splitString "bao kv get" u.script));
|
||||
}
|
||||
{
|
||||
# The reader's own grant covers `swarm/hives/<this hive>/*` and
|
||||
# `swarm/agents/*`; a path outside those answers 403, not "no such key".
|
||||
# So the hive segment is what makes the read reachable, and a rename that
|
||||
# drops it looks correct and fails identically on every boot.
|
||||
name = "the matrix token path sits inside the prefix the reader is granted";
|
||||
ok =
|
||||
let
|
||||
s = baoWithMatrix.systemd.services.swarm-bao-matrix-token.script;
|
||||
in
|
||||
lib.hasInfix "secret/swarm/hives/" s
|
||||
&& lib.hasInfix "/matrix/registration-token" s
|
||||
# The shape it used to have: `matrix` where a principal kind belongs,
|
||||
# which no grant covers.
|
||||
&& !(lib.hasInfix "secret/swarm/matrix/" s);
|
||||
}
|
||||
{
|
||||
# The doctrine three glue files state, as a property a rewrite has to
|
||||
# keep: a client is defined by holding a certificate the store accepts,
|
||||
|
|
|
|||
Loading…
Reference in a new issue