diff --git a/nix/agent-modules/forge.nix b/nix/agent-modules/forge.nix index d83cc1f1..81fb5dd9 100644 --- a/nix/agent-modules/forge.nix +++ b/nix/agent-modules/forge.nix @@ -252,10 +252,18 @@ in # Without this path unit, RemainAfterExit=true would prevent systemd # from ever re-running the service. See # docs/agent-lifecycle/persistence.md::forge-avatar-sync. + # ⚠️ This agent's own token, not a glob over `/agents/*/`. Every agent's + # state dir is visible from inside every container, so a wildcard here + # watches paths this unit has no business reacting to: each sibling's + # token appearing re-fires *this* agent's sync, and enough of them + # arriving at once trips systemd's start rate limit — leaving a red + # `[FAILED]` on every boot after the upload has already succeeded. + # The service reads `$HYPERHIVE_STATE_DIR/forge-token`; this is the same + # file, spelled the way `tea-login` above already spells it. systemd.paths.forge-avatar-sync = lib.mkIf (config.hyperhive.icon != null) { description = "trigger forge-avatar-sync when forge-token appears"; wantedBy = [ "multi-user.target" ]; - pathConfig.PathExistsGlob = "/agents/*/state/forge-token"; + pathConfig.PathExists = "/agents/${userName}/state/forge-token"; }; # One-shot: hyperhive.icon → Forgejo profile avatar. Shape contract: