diff --git a/Cargo.lock b/Cargo.lock index 8ab275c2..4b0ded9a 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1966,7 +1966,6 @@ dependencies = [ "anyhow", "hive-priv-sock", "libc", - "serde", "serde_json", "tokio", "tracing", diff --git a/docs/agent-lifecycle/persistence.md b/docs/agent-lifecycle/persistence.md index c28f7b15..0560360b 100644 --- a/docs/agent-lifecycle/persistence.md +++ b/docs/agent-lifecycle/persistence.md @@ -618,10 +618,10 @@ Idempotency is **per-account**: an `avatar-icon-hash` file in each account's matrix-sdk `state_dir`. The daemon hashes the PNG bytes and skips the upload when unchanged, because every upload mints a fresh `mxc://` URI that emits a profile state event in every joined room — -re-uploading identical bytes is timeline spam. A dashboard-provisioned -account gets its avatar when the `systemd.paths.hive-matrix-daemon` token -watcher restarts the daemon (which re-runs the per-account bring-up), so -no separate avatar trigger is needed. The daemon swallows avatar failures +re-uploading identical bytes is timeline spam. A swarm-UI-linked +account gets its avatar when the daemon restarts on a changed account +listing (exit 75, which re-runs the per-account bring-up), so no separate +avatar trigger is needed. The daemon swallows avatar failures (logged, non-fatal) so they never break account bring-up or sync. diff --git a/docs/swarm/credentials.md b/docs/swarm/credentials.md index a60443ce..8a216831 100644 --- a/docs/swarm/credentials.md +++ b/docs/swarm/credentials.md @@ -68,6 +68,7 @@ of the cell says how. | `swarm/agents//bao-mtls` | the store's agent PKI mount (`deploy.bao.agentPkiMountPath`), which generates the key, at `swarm-controller`'s request at agent creation | `hive-c0re`, under the hive's own certificate, when it writes the agent's container config | ✅ `swarm-controller`'s five-minute pass re-issues a live agent's leaf once it's past half its validity (45 of 90 days, read from the certificate itself) | ❌ `hive-c0re` reads it when it writes the container config, so the agent presents a new leaf from its next start; the old leaf stays valid until it expires | | `swarm/agents//queue` | `swarm-controller`, at agent creation | `hive-agent` in the agent container, under the agent's own certificate, held in memory — the identity it presents to the swarm queue, naming that one agent rather than its hive | ✅ `swarm-controller`'s five-minute pass re-mints a live agent's secret once it's 45 days old by `minted_at` on the stored object; a secret with no `minted_at` gets one stamped, value unchanged. The pass skips agents declared `Destroyed` — declaring an agent destroyed deletes every version of the path instead, the undo of the mint rather than another one | ✅ `hive-agent` reads the path before its first connect and again on every reconnect attempt, so a reconnect after a re-mint presents the new secret. An open connection keeps the secret it connected with; after a revocation the agent keeps retrying under the queue client's backoff | | `swarm/agents//forge-token` | `swarm-controller`, at agent creation and in a pass every 5 minutes over every agent with a store identity | the agent container itself, under its own certificate, fetched to `/run/hive-agent-forge-token/token` | ✅ the controller re-mints when the stored token is missing or no longer matches the forge (last eight characters and scopes) | ✅ the agent re-fetches on a 10-minute timer | +| `swarm/agents//forge/