swarm-controller: guard the lockdown PATCH against a forge name collision

disable_repo_creation now reads the account once before PATCHing
max_repo_creation/source_id, and fails the node if the email isn't the
{agent}@hyperhive.local marker create_agent_user itself sets. The 409/422
create-fold (#4681) only proves some account with that name exists, not
that this node created it, so a pre-existing non-agent account sharing an
agent's chosen name could otherwise get locked onto local auth with repo
creation disabled. Leaves the fold untouched (Option B, per atlas/argus on
#4693); the read moves into disable_repo_creation instead.

Also fixes the nix-sandboxed cargo-test check: forgejo_api::Forgejo::new
builds a reqwest client that eagerly resolves TLS roots via
rustls-native-certs even for the tests' plain-http loopback stub server,
which panics with "No CA certificates were loaded from the system" in the
CA-less build sandbox. Gives that check's nativeBuildInputs pkgs.cacert and
sets SSL_CERT_FILE, same pattern this repo's runtime deployment already
uses for the same reqwest/rustls resolution.
This commit is contained in:
atlas 2026-09-24 15:11:23 +02:00 • committed by mara
commit 58f50ed506
2 changed files with 144 additions and 12 deletions

View file

@ -156,7 +156,24 @@ in
# per-container toplevels stay fully cached.
cargo-test = craneLib.cargoTest {
src = cleanSrc;
inherit cargoArtifacts nativeBuildInputs;
inherit cargoArtifacts;
# `swarm-controller`'s forge tests build a real `forgejo_api::Forgejo`
# (hence a real `reqwest::Client`) against a loopback stub server, never
# the real forge — but `reqwest`/`rustls` still resolves roots through
# `rustls-native-certs` at *client-build* time, unconditionally, even
# though every request that client ever sends is plain `http://` to
# `127.0.0.1`. The nix build sandbox has no system CA store, so that
# resolution finds zero certs and `ClientBuilder::build()` itself fails
# with "No CA certificates were loaded from the system" — the tests
# never get as far as making a request. Same root cause the runtime
# deployment already works around (see `nix/host-modules/swarm-
# controller.nix`'s `caTrust` comment) and the same fix: give
# `rustls-native-certs` something to find via `SSL_CERT_FILE`. The
# bundle's actual contents don't matter here — nothing in these tests
# ever presents or verifies a real certificate — only that the store is
# non-empty.
nativeBuildInputs = nativeBuildInputs ++ [ pkgs.cacert ];
SSL_CERT_FILE = "${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt";
pname = "hyperhive-workspace";
version = "0.1.0";
cargoTestExtraArgs = "--workspace";