swarm-controller: mint each hive's matrix sender token
A hive whose homeserver runs on another host has no local matrix-appservice-token, so hive-c0re's matrix sweep returned before reaching the store read in ensure_hive_user: no @hive-<name>: token, no Space, no chat room, no invites, and a sweep-health banner. swarm-controller now mints @hive-<name>: with the swarm appservice token for every hive in its directory, as a MintHiveSenderToken job node queued by a five-minute pass, and stores it at swarm/hives/<name>/matrix/sender-token, the same matrix::Credential swarm-matrix-ctl writes there. It is keep-if-live, reusing agent_token's classify/plan: a stored token whoami confirms as @hive-<name>: is left alone, so only an absent or dead one is minted. agent_token's probe and mint steps are lifted into probe_at/mint_at so both passes share them. swarm-matrix-ctl mint still writes the path for its own hive when it is empty. If both mint an empty path at once, one token is invalidated (same pinned device); the next pass classifies it Revoked and re-mints. hive-c0re's ensure_all no longer returns when there is no local as_token. ensure_hive_user reads the store first on every sweep and overwrites its token file when the store's token differs, keeps the file when the store has none, mints with the local as_token only when neither holds one, and fails with one error when there is nothing at all. The decision is sender_source, unit-tested. The controller's bao policy gains create/read/update on swarm/hives/+/matrix/sender-token (`+`, since `*` is a glob only at the end of a path), pinned in module-eval. Refs #4427
This commit is contained in:
parent
9a5a947f8d
commit
78d8d69c7f
10 changed files with 504 additions and 80 deletions
|
|
@ -398,29 +398,36 @@ fn encode_room_id_for_url(room_id: &str) -> String {
|
|||
/// appservice registration's `sender_localpart`, and everything the hive
|
||||
/// provisions with it, it provisions as the creator of those rooms.
|
||||
///
|
||||
/// Idempotent — skips the account work when the token file already exists
|
||||
/// and is non-empty.
|
||||
/// Where the token comes from is [`sender_source`]'s decision. The **swarm
|
||||
/// secret store** wins whenever it holds one: `swarm-controller` mints it
|
||||
/// there (and `swarm-matrix-ctl` on the homeserver's own host), keeps it while
|
||||
/// it is live and replaces it when it is not, so the file follows the store
|
||||
/// rather than outliving it. That is also what lets a hive that holds no
|
||||
/// `as_token` have an account at all. The file is kept when the store has
|
||||
/// nothing or cannot be reached, and the mint ladder below is the fallback
|
||||
/// when neither holds a token and this hive has an `as_token`.
|
||||
///
|
||||
/// The token is taken from the **swarm secret store** when it is there:
|
||||
/// `swarm-matrix-ctl`, the oneshot inside the matrix container, publishes
|
||||
/// it under an identity of its own, and taking it from there is what lets a
|
||||
/// hive that holds no `as_token` have an admin at all. The mint ladder below
|
||||
/// stays as the fallback for a store that is empty, unconfigured or
|
||||
/// unreachable — which is every swarm whose matrix container predates that
|
||||
/// binary.
|
||||
pub async fn ensure_hive_user(client: &reqwest::Client, as_token: &str) -> Result<()> {
|
||||
/// # Errors
|
||||
/// When no token can be had — nothing in the store or the file, and no
|
||||
/// `as_token` — or when a step of the mint ladder or the file write fails.
|
||||
pub async fn ensure_hive_user(client: &reqwest::Client, as_token: Option<&str>) -> Result<()> {
|
||||
use std::os::unix::fs::PermissionsExt;
|
||||
let path = sender_token_path();
|
||||
if path.exists()
|
||||
&& let Ok(existing) = std::fs::read_to_string(&path)
|
||||
&& !existing.trim().is_empty()
|
||||
{
|
||||
tracing::debug!("matrix: the sender token is already present");
|
||||
return Ok(());
|
||||
}
|
||||
if let Some(token) = stored_sender_token().await {
|
||||
return persist_sender_token(&path, &token);
|
||||
}
|
||||
let on_disk = std::fs::read_to_string(&path).ok();
|
||||
let stored = stored_sender_token().await;
|
||||
let as_token = match sender_source(stored.as_deref(), on_disk.as_deref(), as_token) {
|
||||
SenderSource::Keep => {
|
||||
tracing::debug!("matrix: the sender token is already present");
|
||||
return Ok(());
|
||||
}
|
||||
SenderSource::Store(token) => return persist_sender_token(&path, token),
|
||||
SenderSource::Mint(as_token) => as_token,
|
||||
SenderSource::Unavailable => anyhow::bail!(
|
||||
"matrix: no sender token in the swarm store or at {}, and no appservice \
|
||||
token on this host to mint one with",
|
||||
path.display()
|
||||
),
|
||||
};
|
||||
// Per hive, and fatal when it cannot be derived: the fallback ladder below
|
||||
// must not mint under some other hive's name.
|
||||
let localpart = hive_localpart()?;
|
||||
|
|
@ -473,6 +480,39 @@ pub async fn ensure_hive_user(client: &reqwest::Client, as_token: &str) -> Resul
|
|||
persist_sender_token(&path, &access_token)
|
||||
}
|
||||
|
||||
/// What [`ensure_hive_user`] does about the sender token this sweep.
|
||||
#[derive(Debug, PartialEq, Eq)]
|
||||
enum SenderSource<'a> {
|
||||
/// The file already holds the token to use.
|
||||
Keep,
|
||||
/// Write the store's token to the file.
|
||||
Store(&'a str),
|
||||
/// Mint one with this hive's own appservice token.
|
||||
Mint(&'a str),
|
||||
/// Nothing to take and nothing to mint with.
|
||||
Unavailable,
|
||||
}
|
||||
|
||||
/// Decide [`ensure_hive_user`]'s step from the store's token, the file's
|
||||
/// content and this hive's `as_token`, each `None` when absent. Blank counts
|
||||
/// as absent.
|
||||
fn sender_source<'a>(
|
||||
stored: Option<&'a str>,
|
||||
on_disk: Option<&str>,
|
||||
as_token: Option<&'a str>,
|
||||
) -> SenderSource<'a> {
|
||||
let present = |s: &&str| !s.trim().is_empty();
|
||||
let stored = stored.map(str::trim).filter(present);
|
||||
let on_disk = on_disk.map(str::trim).filter(present);
|
||||
match (stored, on_disk, as_token.filter(present)) {
|
||||
(Some(s), Some(d), _) if s == d => SenderSource::Keep,
|
||||
(Some(s), _, _) => SenderSource::Store(s),
|
||||
(None, Some(_), _) => SenderSource::Keep,
|
||||
(None, None, Some(a)) => SenderSource::Mint(a),
|
||||
(None, None, None) => SenderSource::Unavailable,
|
||||
}
|
||||
}
|
||||
|
||||
/// Write the appservice sender account's access token to `path`, 0600, creating the
|
||||
/// directory if it is not there.
|
||||
///
|
||||
|
|
@ -493,8 +533,8 @@ fn persist_sender_token(path: &std::path::Path, access_token: &str) -> Result<()
|
|||
Ok(())
|
||||
}
|
||||
|
||||
/// Fetch the sender token `swarm-matrix-ctl` published, under
|
||||
/// this hive's own store identity.
|
||||
/// Fetch the sender token `swarm-controller` (or `swarm-matrix-ctl`)
|
||||
/// published, under this hive's own store identity.
|
||||
///
|
||||
/// The cert role is the hive's name, straight out of `HYPERHIVE_HIVE_NAME` —
|
||||
/// the same role string `workers::credential` logs in with, and already in
|
||||
|
|
@ -506,10 +546,10 @@ fn persist_sender_token(path: &std::path::Path, access_token: &str) -> Result<()
|
|||
///
|
||||
/// `None`, never an error, for every way this can come up empty — no hive
|
||||
/// name, no `BAO_*` identity, an unreachable store, nothing at the path. All
|
||||
/// four mean the same thing to the caller ("mint it the old way"), and three
|
||||
/// of them are the ordinary state of a swarm that has not deployed `swarm-matrix-ctl`
|
||||
/// yet, so raising would turn a supported deployment into a warning every
|
||||
/// sweep.
|
||||
/// four mean the same thing to the caller ("keep the file, or mint it the old
|
||||
/// way"), and three of them are the ordinary state of a swarm with no store
|
||||
/// token for this hive yet, so raising would turn a supported deployment into
|
||||
/// a warning every sweep.
|
||||
///
|
||||
/// 🩸 Logs the store **path** and never the value.
|
||||
async fn stored_sender_token() -> Option<String> {
|
||||
|
|
@ -535,15 +575,15 @@ async fn stored_sender_token() -> Option<String> {
|
|||
.await
|
||||
{
|
||||
Ok(credential) if !credential.value.trim().is_empty() => {
|
||||
tracing::info!(%path, "matrix: taking the sender token from the swarm store");
|
||||
tracing::debug!(%path, "matrix: read the sender token from the swarm store");
|
||||
Some(credential.value)
|
||||
}
|
||||
Ok(_) => {
|
||||
tracing::warn!(%path, "matrix: the stored sender token is empty; minting instead");
|
||||
tracing::warn!(%path, "matrix: the stored sender token is empty");
|
||||
None
|
||||
}
|
||||
Err(e) => {
|
||||
tracing::debug!(%path, error = %e, "matrix: no sender token in the store; minting instead");
|
||||
tracing::debug!(%path, error = %e, "matrix: no sender token in the store");
|
||||
None
|
||||
}
|
||||
}
|
||||
|
|
@ -1239,15 +1279,12 @@ pub async fn ensure_all() -> bool {
|
|||
return true;
|
||||
}
|
||||
let mut ok = true;
|
||||
// Loud and non-destructive: with no appservice token this sweep can
|
||||
// create nothing, so it does nothing.
|
||||
let as_token = match read_appservice_token() {
|
||||
Ok(t) => t,
|
||||
Err(e) => {
|
||||
tracing::warn!(error = ?e, "matrix: no appservice token; skipping the user sweep");
|
||||
return false;
|
||||
}
|
||||
};
|
||||
// Absent on every hive whose homeserver runs elsewhere. Only the sender
|
||||
// token's mint fallback needs it; `ensure_hive_user` fails, and says so,
|
||||
// when the store has no token either.
|
||||
let as_token = read_appservice_token()
|
||||
.inspect_err(|e| tracing::debug!(error = ?e, "matrix: no local appservice token"))
|
||||
.ok();
|
||||
// One HTTP client for the whole sweep.
|
||||
let client = match reqwest::Client::builder()
|
||||
.timeout(std::time::Duration::from_secs(HTTP_TIMEOUT_SECS))
|
||||
|
|
@ -1263,7 +1300,7 @@ pub async fn ensure_all() -> bool {
|
|||
// THROUGH it (the Space, the chat room and every invite are sent with
|
||||
// its token) — as an ordinary user that created those rooms, not as a
|
||||
// homeserver admin.
|
||||
if let Err(e) = ensure_hive_user(&client, &as_token).await {
|
||||
if let Err(e) = ensure_hive_user(&client, as_token.as_deref()).await {
|
||||
tracing::warn!(error = ?e, "matrix: ensure_hive_user failed");
|
||||
ok = false;
|
||||
}
|
||||
|
|
@ -1375,6 +1412,56 @@ async fn provision_space(client: &reqwest::Client, agent_names: &[String]) -> bo
|
|||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn a_remote_hive_takes_the_store_token_without_an_appservice_token() {
|
||||
assert_eq!(
|
||||
sender_source(Some("tok"), None, None),
|
||||
SenderSource::Store("tok")
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_store_token_replaces_a_different_file_token() {
|
||||
// The swarm re-minted a dead token; the file must follow it.
|
||||
assert_eq!(
|
||||
sender_source(Some("new\n"), Some("old\n"), Some("as")),
|
||||
SenderSource::Store("new")
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_file_matching_the_store_is_kept() {
|
||||
// Trailing newline on disk is how `persist_sender_token` writes it.
|
||||
assert_eq!(
|
||||
sender_source(Some("tok"), Some("tok\n"), None),
|
||||
SenderSource::Keep
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn with_nothing_in_the_store_the_file_is_kept() {
|
||||
assert_eq!(
|
||||
sender_source(None, Some("tok\n"), Some("as")),
|
||||
SenderSource::Keep
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn with_no_token_anywhere_the_appservice_token_mints() {
|
||||
assert_eq!(
|
||||
sender_source(None, Some(" \n"), Some("as")),
|
||||
SenderSource::Mint("as")
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn with_no_token_and_no_appservice_token_nothing_is_available() {
|
||||
assert_eq!(
|
||||
sender_source(Some(""), None, Some("")),
|
||||
SenderSource::Unavailable
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn random_hex_is_well_formed_and_correct_length() {
|
||||
let h = random_hex(16).expect("/dev/urandom readable");
|
||||
|
|
|
|||
|
|
@ -593,7 +593,7 @@ async fn handle_matrix_sync_admin() -> Result<HostResponse> {
|
|||
let as_token =
|
||||
crate::matrix::read_appservice_token().context("read matrix appservice token")?;
|
||||
let client = matrix_http_client()?;
|
||||
crate::matrix::ensure_hive_user(&client, &as_token)
|
||||
crate::matrix::ensure_hive_user(&client, Some(&as_token))
|
||||
.await
|
||||
.context("matrix sync-admin")?;
|
||||
let path = crate::matrix::sender_token_path();
|
||||
|
|
|
|||
Loading…
Reference in a new issue