diff --git a/docs/trust-boundary/security.md b/docs/trust-boundary/security.md index 6fc974b8..29e16635 100644 --- a/docs/trust-boundary/security.md +++ b/docs/trust-boundary/security.md @@ -296,7 +296,6 @@ known operations; there is no arbitrary command pass-through: | `DaemonReload` | `systemctl daemon-reload` | | `RunForgeAdmin` | `nixos-container run hive-forge -- runuser -u forgejo -- forgejo admin ` | | `WriteAgentMatrixToken` | write `0600` credential file into agent state dir | -| `RestartMatrixDaemon` | `systemctl --machine=h- restart hive-matrix-daemon.service` | | `ControlInfraContainer` | `systemctl container@.service` — the `InfraContainer` enum is the allowlist, and serde rejects unknown names at the wire boundary (`hive-c0re` has no variant, so no request can name it) | | `SyncAgentTmpfiles` | legacy: unlink `/etc/tmpfiles.d/hyperhive-agents.conf` and return `Ok`; kept one release for an older hive-c0re | | `SetAgentPaused` | create / remove the `//harness/paused` marker that parks an agent's turn loop | diff --git a/hive-priv-sock/src/lib.rs b/hive-priv-sock/src/lib.rs index da174db2..b4b13fe6 100644 --- a/hive-priv-sock/src/lib.rs +++ b/hive-priv-sock/src/lib.rs @@ -562,15 +562,6 @@ pub enum PrivRequest { label: String, }, - /// Restart `hive-matrix-daemon.service` inside an agent container via - /// `systemctl --machine=h- restart hive-matrix-daemon.service`. - /// Used by hive-c0re to kick the daemon after a successful token write - /// so it picks up the new credential without a full container restart. - RestartMatrixDaemon { - /// Logical agent name (validated by `validate_agent_name`). - agent_name: String, - }, - /// Register the hive-ci Forgejo Actions runner: write the registration /// token to the host-side `/run/hive-ci/runner-token` env-file (root-owned, /// bind-mounted read-only into the container) as `TOKEN=`, then diff --git a/hive-priv/src/main.rs b/hive-priv/src/main.rs index c978f4b2..2ad506d7 100644 --- a/hive-priv/src/main.rs +++ b/hive-priv/src/main.rs @@ -432,10 +432,6 @@ async fn exec( ref label, } => delete_extra_forge_account(agent_name, label), - PrivRequest::RestartMatrixDaemon { ref agent_name } => { - restart_matrix_daemon(agent_name).await - } - PrivRequest::RegisterCiRunner { ref token } => register_ci_runner(token).await, PrivRequest::ControlInfraContainer { container, action } => { @@ -1262,30 +1258,6 @@ async fn daemon_reload() -> Result<(String, String)> { Ok((String::new(), String::new())) } -/// `RestartMatrixDaemon` — restart the matrix daemon unit inside the -/// agent's container. -async fn restart_matrix_daemon(agent_name: &str) -> Result<(String, String)> { - validate_agent_name(agent_name)?; - let machine = format!("--machine=h-{agent_name}"); - let unit = "hive-matrix-daemon.service"; - let out = Command::new("systemctl") - .args([&machine, "restart", unit]) - .output() - .await - .with_context(|| format!("systemctl restart {unit} in container h-{agent_name}"))?; - if !out.status.success() { - bail!( - "systemctl restart {unit} in h-{agent_name} exited {}: {}", - out.status, - String::from_utf8_lossy(&out.stderr).trim() - ); - } - Ok(( - String::from_utf8_lossy(&out.stdout).into_owned(), - String::from_utf8_lossy(&out.stderr).into_owned(), - )) -} - /// Host path to the hive-ci runner's persisted registration credentials. /// /// Paired with `hive-c0re`'s `forge::ci_runner::RUNNER_FILE`, which reads the