hive-priv: remove the RestartMatrixDaemon command
Its only client was hive-c0re's matrix-account-login handler, removed earlier on this branch, so nothing sends `restart_matrix_daemon` any more. Drops the `PrivRequest` variant, the hive-priv handler and its `systemctl --machine=h-<agent> restart hive-matrix-daemon.service` helper, and the row in the hive-priv op table in security.md. `PrivRequest` is internally tagged by `op` name, so no other variant's encoding changes. A new token file still re-fires the daemon through its `matrix-token*` path unit. Refs #4348
This commit is contained in:
parent
f6ac007dc0
commit
1d8ec00ddc
3 changed files with 0 additions and 38 deletions
|
|
@ -296,7 +296,6 @@ known operations; there is no arbitrary command pass-through:
|
||||||
| `DaemonReload` | `systemctl daemon-reload` |
|
| `DaemonReload` | `systemctl daemon-reload` |
|
||||||
| `RunForgeAdmin` | `nixos-container run hive-forge -- runuser -u forgejo -- forgejo admin <args>` |
|
| `RunForgeAdmin` | `nixos-container run hive-forge -- runuser -u forgejo -- forgejo admin <args>` |
|
||||||
| `WriteAgentMatrixToken` | write `0600` credential file into agent state dir |
|
| `WriteAgentMatrixToken` | write `0600` credential file into agent state dir |
|
||||||
| `RestartMatrixDaemon` | `systemctl --machine=h-<name> restart hive-matrix-daemon.service` |
|
|
||||||
| `ControlInfraContainer` | `systemctl <action> container@<container>.service` — the `InfraContainer` enum is the allowlist, and serde rejects unknown names at the wire boundary (`hive-c0re` has no variant, so no request can name it) |
|
| `ControlInfraContainer` | `systemctl <action> container@<container>.service` — the `InfraContainer` enum is the allowlist, and serde rejects unknown names at the wire boundary (`hive-c0re` has no variant, so no request can name it) |
|
||||||
| `SyncAgentTmpfiles` | legacy: unlink `/etc/tmpfiles.d/hyperhive-agents.conf` and return `Ok`; kept one release for an older hive-c0re |
|
| `SyncAgentTmpfiles` | legacy: unlink `/etc/tmpfiles.d/hyperhive-agents.conf` and return `Ok`; kept one release for an older hive-c0re |
|
||||||
| `SetAgentPaused` | create / remove the `<state>/<name>/harness/paused` marker that parks an agent's turn loop |
|
| `SetAgentPaused` | create / remove the `<state>/<name>/harness/paused` marker that parks an agent's turn loop |
|
||||||
|
|
|
||||||
|
|
@ -562,15 +562,6 @@ pub enum PrivRequest {
|
||||||
label: String,
|
label: String,
|
||||||
},
|
},
|
||||||
|
|
||||||
/// Restart `hive-matrix-daemon.service` inside an agent container via
|
|
||||||
/// `systemctl --machine=h-<agent_name> restart hive-matrix-daemon.service`.
|
|
||||||
/// Used by hive-c0re to kick the daemon after a successful token write
|
|
||||||
/// so it picks up the new credential without a full container restart.
|
|
||||||
RestartMatrixDaemon {
|
|
||||||
/// Logical agent name (validated by `validate_agent_name`).
|
|
||||||
agent_name: String,
|
|
||||||
},
|
|
||||||
|
|
||||||
/// Register the hive-ci Forgejo Actions runner: write the registration
|
/// Register the hive-ci Forgejo Actions runner: write the registration
|
||||||
/// token to the host-side `/run/hive-ci/runner-token` env-file (root-owned,
|
/// token to the host-side `/run/hive-ci/runner-token` env-file (root-owned,
|
||||||
/// bind-mounted read-only into the container) as `TOKEN=<token>`, then
|
/// bind-mounted read-only into the container) as `TOKEN=<token>`, then
|
||||||
|
|
|
||||||
|
|
@ -432,10 +432,6 @@ async fn exec(
|
||||||
ref label,
|
ref label,
|
||||||
} => delete_extra_forge_account(agent_name, label),
|
} => delete_extra_forge_account(agent_name, label),
|
||||||
|
|
||||||
PrivRequest::RestartMatrixDaemon { ref agent_name } => {
|
|
||||||
restart_matrix_daemon(agent_name).await
|
|
||||||
}
|
|
||||||
|
|
||||||
PrivRequest::RegisterCiRunner { ref token } => register_ci_runner(token).await,
|
PrivRequest::RegisterCiRunner { ref token } => register_ci_runner(token).await,
|
||||||
|
|
||||||
PrivRequest::ControlInfraContainer { container, action } => {
|
PrivRequest::ControlInfraContainer { container, action } => {
|
||||||
|
|
@ -1262,30 +1258,6 @@ async fn daemon_reload() -> Result<(String, String)> {
|
||||||
Ok((String::new(), String::new()))
|
Ok((String::new(), String::new()))
|
||||||
}
|
}
|
||||||
|
|
||||||
/// `RestartMatrixDaemon` — restart the matrix daemon unit inside the
|
|
||||||
/// agent's container.
|
|
||||||
async fn restart_matrix_daemon(agent_name: &str) -> Result<(String, String)> {
|
|
||||||
validate_agent_name(agent_name)?;
|
|
||||||
let machine = format!("--machine=h-{agent_name}");
|
|
||||||
let unit = "hive-matrix-daemon.service";
|
|
||||||
let out = Command::new("systemctl")
|
|
||||||
.args([&machine, "restart", unit])
|
|
||||||
.output()
|
|
||||||
.await
|
|
||||||
.with_context(|| format!("systemctl restart {unit} in container h-{agent_name}"))?;
|
|
||||||
if !out.status.success() {
|
|
||||||
bail!(
|
|
||||||
"systemctl restart {unit} in h-{agent_name} exited {}: {}",
|
|
||||||
out.status,
|
|
||||||
String::from_utf8_lossy(&out.stderr).trim()
|
|
||||||
);
|
|
||||||
}
|
|
||||||
Ok((
|
|
||||||
String::from_utf8_lossy(&out.stdout).into_owned(),
|
|
||||||
String::from_utf8_lossy(&out.stderr).into_owned(),
|
|
||||||
))
|
|
||||||
}
|
|
||||||
|
|
||||||
/// Host path to the hive-ci runner's persisted registration credentials.
|
/// Host path to the hive-ci runner's persisted registration credentials.
|
||||||
///
|
///
|
||||||
/// Paired with `hive-c0re`'s `forge::ci_runner::RUNNER_FILE`, which reads the
|
/// Paired with `hive-c0re`'s `forge::ci_runner::RUNNER_FILE`, which reads the
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue