hive-priv: remove the RestartMatrixDaemon command
Its only client was hive-c0re's matrix-account-login handler, removed earlier on this branch, so nothing sends `restart_matrix_daemon` any more. Drops the `PrivRequest` variant, the hive-priv handler and its `systemctl --machine=h-<agent> restart hive-matrix-daemon.service` helper, and the row in the hive-priv op table in security.md. `PrivRequest` is internally tagged by `op` name, so no other variant's encoding changes. A new token file still re-fires the daemon through its `matrix-token*` path unit. Refs #4348
This commit is contained in:
parent
f6ac007dc0
commit
1d8ec00ddc
3 changed files with 0 additions and 38 deletions
|
|
@ -296,7 +296,6 @@ known operations; there is no arbitrary command pass-through:
|
|||
| `DaemonReload` | `systemctl daemon-reload` |
|
||||
| `RunForgeAdmin` | `nixos-container run hive-forge -- runuser -u forgejo -- forgejo admin <args>` |
|
||||
| `WriteAgentMatrixToken` | write `0600` credential file into agent state dir |
|
||||
| `RestartMatrixDaemon` | `systemctl --machine=h-<name> restart hive-matrix-daemon.service` |
|
||||
| `ControlInfraContainer` | `systemctl <action> container@<container>.service` — the `InfraContainer` enum is the allowlist, and serde rejects unknown names at the wire boundary (`hive-c0re` has no variant, so no request can name it) |
|
||||
| `SyncAgentTmpfiles` | legacy: unlink `/etc/tmpfiles.d/hyperhive-agents.conf` and return `Ok`; kept one release for an older hive-c0re |
|
||||
| `SetAgentPaused` | create / remove the `<state>/<name>/harness/paused` marker that parks an agent's turn loop |
|
||||
|
|
|
|||
Loading…
Reference in a new issue