feat(#2862): push a snapshot to a peer hive's store over the mesh

Adds the caller the fd-passing machinery existed for: hivectl agent
<name> subvol snapshot push --peer <hive> resolves the peer, connects
to its snapshot store, writes the agent header, and hands the connected
socket to hive-priv, which runs btrfs send straight into it.

The split keeps the root helper ignorant. Everything that involves
knowing where a peer is, what the wire protocol looks like, and which
hive to trust happens in the unprivileged daemon; hive-priv only ever
receives an already-open descriptor. Once btrfs send starts, neither
process is in the data path, so a multi-gigabyte transfer costs no
per-byte work and survives a hive-c0re restart.

call_with_fd takes the descriptor by value and closes it as soon as the
kernel has it. A socket stays open until every copy closes, so holding
one back would leave the receiver waiting for an EOF that never comes:
btrfs receive blocks and this side reports success for a transfer the
peer never committed. Ownership makes that unrepresentable.

The peer's store port is a new swarm.peers.<domain>.snapshotStorePort
option rather than a constant matching the module default. A pushing
hive cannot read the receiver's configuration, so assuming 51821 would
push at a port nobody promised to listen on; absent, the push fails
naming the option. swarm_peers parses the mesh address the host module
has always rendered into HYPERHIVE_PEERS but nothing read.
This commit is contained in:
atlas 2026-07-31 21:40:34 +02:00 committed by mara
commit 282bbc3709
10 changed files with 546 additions and 9 deletions

View file

@ -375,6 +375,23 @@ pub enum HostRequest {
parent: Option<String>,
dest: String,
},
/// Push a snapshot to a peer hive's snapshot store over the
/// WireGuard mesh (`hivectl agent <name> subvol snapshot push`).
/// The network sibling of [`HostRequest::SendSnapshot`]: same
/// snapshot and optional incremental `parent`, but the stream goes
/// to `peer`'s receiver instead of a local file.
///
/// `peer` is a domain from `services.hyperhive.swarm.peers`; the
/// daemon resolves its mesh address and store port from there and
/// fails if the peer declares neither. Bare success — nothing is
/// written on this host to report a path for.
PushSnapshot {
name: Ident,
label: String,
#[serde(default)]
parent: Option<String>,
peer: String,
},
}
/// One agent's btrfs qgroup usage row — the [`HostRequest::QuotaShow`]