swarm-controller: mint each hive's matrix sender token
A hive whose homeserver runs on another host has no local matrix-appservice-token, so hive-c0re's matrix sweep returned before reaching the store read in ensure_hive_user: no @hive-<name>: token, no Space, no chat room, no invites, and a sweep-health banner. swarm-controller now mints @hive-<name>: with the swarm appservice token for every hive in its directory, as a MintHiveSenderToken job node queued by a five-minute pass, and stores it at swarm/hives/<name>/matrix/sender-token, the same matrix::Credential swarm-matrix-ctl writes there. It is keep-if-live, reusing agent_token's classify/plan: a stored token whoami confirms as @hive-<name>: is left alone, so only an absent or dead one is minted. agent_token's probe and mint steps are lifted into probe_at/mint_at so both passes share them. swarm-matrix-ctl mint still writes the path for its own hive when it is empty. If both mint an empty path at once, one token is invalidated (same pinned device); the next pass classifies it Revoked and re-mints. hive-c0re's ensure_all no longer returns when there is no local as_token. ensure_hive_user reads the store first on every sweep and overwrites its token file when the store's token differs, keeps the file when the store has none, mints with the local as_token only when neither holds one, and fails with one error when there is nothing at all. The decision is sender_source, unit-tested. The controller's bao policy gains create/read/update on swarm/hives/+/matrix/sender-token (`+`, since `*` is a glob only at the end of a path), pinned in module-eval. Refs #4427
This commit is contained in:
parent
9a5a947f8d
commit
78d8d69c7f
10 changed files with 504 additions and 80 deletions
|
|
@ -1121,10 +1121,9 @@ let
|
|||
# `swarm_secret_client::path::ROOT` and `agents` is
|
||||
# `Kind::Agent.as_str()`, both of which that crate pins in its own test.
|
||||
#
|
||||
# The grant is still the agent kind alone because nothing writes another
|
||||
# one yet. It widens when a path outside `agents/` gains a writer, not
|
||||
# when the kinds are declared.
|
||||
name = "the controller may write agent credentials, and only under the agent prefix";
|
||||
# The only other kind it writes is one leaf per hive, pinned below. A
|
||||
# grant widens when a path gains a writer, not when a kind is declared.
|
||||
name = "the controller may write agent credentials, and no whole tree beyond them";
|
||||
ok =
|
||||
let
|
||||
s = baoGrantHere.systemd.services.swarm-bao-controller-policy.script;
|
||||
|
|
@ -1147,6 +1146,21 @@ let
|
|||
in
|
||||
lib.hasInfix "path \"secret/data/swarm/agents/*\" {\n capabilities = [\"create\", \"read\", \"update\"]" s;
|
||||
}
|
||||
{
|
||||
# `matrix_account::hive_sender` writes every hive's sender token, and
|
||||
# nothing else under `hives/`: a hive's appservice token sits beside
|
||||
# it. `+` is one segment, which keeps this to the one leaf; a `*` is a
|
||||
# glob only at the end of a path. Pinned as the whole stanza, so an
|
||||
# added capability fails.
|
||||
name = "the controller writes each hive's sender token and nothing else under hives";
|
||||
ok =
|
||||
let
|
||||
s = baoGrantHere.systemd.services.swarm-bao-controller-policy.script;
|
||||
in
|
||||
lib.hasInfix "path \"secret/data/swarm/hives/+/matrix/sender-token\" {\n capabilities = [\"create\", \"read\", \"update\"]\n}" s
|
||||
&& !(lib.hasInfix "secret/data/swarm/hives/*" s)
|
||||
&& !(lib.hasInfix "secret/metadata/swarm/hives" s);
|
||||
}
|
||||
{
|
||||
# Revocation, and the reason it is a stanza of its own: `delete` on the
|
||||
# `data/` path soft-deletes the newest version and leaves earlier ones
|
||||
|
|
|
|||
Loading…
Reference in a new issue