argus on #676 🔴: this PR deletes agent-base.nix + manager.nix and moves the harness service to harness-base.nix without carrying forward damocles's #672 fix (which adds `/run/wrappers/bin` to the service PATH so the setuid sudo wrapper resolves before the bare nix-store binary). Pull the #672 fix forward: prepend `/run/wrappers/bin` to the unified harness service's path list. Same shape as damocles's diff on agent-base + manager, but applied once in harness-base.nix. Without this, post-#658 `sudo` inside the container resolves to the un-setuid nix-store binary and refuses with "must be owned by uid 0 and have the setuid bit set" even when `hyperhive.user.passwordlessSudo = true` is configured. Verified via `nix eval`: - agent-base.systemd.services.hive-ag3nt.path[0] = "/run/wrappers/bin" ✓ - manager.systemd.services.hive-m1nd.path[0] = "/run/wrappers/bin" ✓ #672 (damocles) supersedes when this lands — the two changes are equivalent and the consolidated harness-base.nix is now the canonical home for the fix.
This commit is contained in:
parent
0951cd1b3d
commit
2e9c50ecc7
1 changed files with 15 additions and 1 deletions
|
|
@ -1252,7 +1252,21 @@ in
|
||||||
# access to everything declared in `systemPackages` — including
|
# access to everything declared in `systemPackages` — including
|
||||||
# anything an agent adds to its own `agent.nix` — without having
|
# anything an agent adds to its own `agent.nix` — without having
|
||||||
# to touch the service definition.
|
# to touch the service definition.
|
||||||
path = [ "/run/current-system/sw" ];
|
#
|
||||||
|
# `/run/wrappers/bin` prepended so the `security.wrappers`
|
||||||
|
# setuid shims (notably `sudo`) resolve before the bare
|
||||||
|
# nix-store binaries in `/run/current-system/sw/bin`.
|
||||||
|
# Post-#658 the harness runs as the per-agent user — without
|
||||||
|
# the wrapper dir on PATH, `sudo` resolves to the un-setuid
|
||||||
|
# nix-store binary and refuses with "must be owned by uid 0
|
||||||
|
# and have the setuid bit set" even when
|
||||||
|
# `hyperhive.user.passwordlessSudo = true` is configured
|
||||||
|
# (#672 fixup pulled forward into this PR to avoid the
|
||||||
|
# regression argus flagged on #676).
|
||||||
|
path = [
|
||||||
|
"/run/wrappers/bin"
|
||||||
|
"/run/current-system/sw"
|
||||||
|
];
|
||||||
environment = {
|
environment = {
|
||||||
SHELL = "${pkgs.bashInteractive}/bin/bash";
|
SHELL = "${pkgs.bashInteractive}/bin/bash";
|
||||||
# `HOME` defaults to `/` for systemd services without a User=
|
# `HOME` defaults to `/` for systemd services without a User=
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue