swarm-controller: mint each hive's matrix sender token
A hive whose homeserver runs on another host has no local matrix-appservice-token, so hive-c0re's matrix sweep returned before reaching the store read in ensure_hive_user: no @hive-<name>: token, no Space, no chat room, no invites, and a sweep-health banner. swarm-controller now mints @hive-<name>: with the swarm appservice token for every hive in its directory, as a MintHiveSenderToken job node queued by a five-minute pass, and stores it at swarm/hives/<name>/matrix/sender-token, the same matrix::Credential swarm-matrix-ctl writes there. It is keep-if-live, reusing agent_token's classify/plan: a stored token whoami confirms as @hive-<name>: is left alone, so only an absent or dead one is minted. agent_token's probe and mint steps are lifted into probe_at/mint_at so both passes share them. swarm-matrix-ctl mint still writes the path for its own hive when it is empty. If both mint an empty path at once, one token is invalidated (same pinned device); the next pass classifies it Revoked and re-mints. hive-c0re's ensure_all no longer returns when there is no local as_token. ensure_hive_user reads the store first on every sweep and overwrites its token file when the store's token differs, keeps the file when the store has none, mints with the local as_token only when neither holds one, and fails with one error when there is nothing at all. The decision is sender_source, unit-tested. The controller's bao policy gains create/read/update on swarm/hives/+/matrix/sender-token (`+`, since `*` is a glob only at the end of a path), pinned in module-eval. Refs #4427
This commit is contained in:
parent
9a5a947f8d
commit
78d8d69c7f
10 changed files with 504 additions and 80 deletions
|
|
@ -123,6 +123,10 @@ enum SwarmNodeKind {
|
|||
/// Carries no hive: the path it writes has no hive segment, so an agent
|
||||
/// that moves between hives keeps one matrix identity.
|
||||
MintAgentMatrixAccount { agent: String },
|
||||
/// Make sure `hive`'s sender account (`@hive-<hive>:`) holds a live token
|
||||
/// in the swarm store, where that hive's matrix sweep reads it. See
|
||||
/// `matrix_account::hive_sender`.
|
||||
MintHiveSenderToken { hive: String },
|
||||
/// Re-mint `agent`'s queue secret if it is still stored and old enough.
|
||||
/// See `agent_renewal`.
|
||||
///
|
||||
|
|
@ -154,6 +158,7 @@ impl hive_jobq_wire::WireNode for SwarmNodeKind {
|
|||
SwarmNodeKind::MintAgentIdentity { .. } => "mint_agent_identity".to_owned(),
|
||||
SwarmNodeKind::MintAgentForgeToken { .. } => "mint_agent_forge_token".to_owned(),
|
||||
SwarmNodeKind::MintAgentMatrixAccount { .. } => "mint_agent_matrix_account".to_owned(),
|
||||
SwarmNodeKind::MintHiveSenderToken { .. } => "mint_hive_sender_token".to_owned(),
|
||||
SwarmNodeKind::RenewAgentQueueCredential { .. } => {
|
||||
"renew_agent_queue_credential".to_owned()
|
||||
}
|
||||
|
|
@ -181,6 +186,7 @@ impl hive_jobq_wire::WireNode for SwarmNodeKind {
|
|||
| SwarmNodeKind::RenewAgentQueueCredential { agent } => {
|
||||
serde_json::json!({ "agent": agent })
|
||||
}
|
||||
SwarmNodeKind::MintHiveSenderToken { hive } => serde_json::json!({ "hive": hive }),
|
||||
SwarmNodeKind::TriggerDeploy { hive, agent }
|
||||
| SwarmNodeKind::SetAgentWanted { hive, agent } => {
|
||||
serde_json::json!({ "agent": agent, "hive": hive })
|
||||
|
|
@ -329,6 +335,9 @@ async fn run_swarm_node(
|
|||
SwarmNodeKind::MintAgentMatrixAccount { agent } => {
|
||||
mint_matrix_account(deps.matrix_homeserver.as_deref(), &agent).await
|
||||
}
|
||||
SwarmNodeKind::MintHiveSenderToken { hive } => {
|
||||
mint_hive_sender(deps.matrix_homeserver.as_deref(), &hive).await
|
||||
}
|
||||
SwarmNodeKind::RenewAgentQueueCredential { agent } => {
|
||||
match agent_renewal::renew(&agent).await {
|
||||
Ok(()) => Outcome::Done,
|
||||
|
|
@ -408,6 +417,23 @@ async fn mint_matrix_account(
|
|||
}
|
||||
}
|
||||
|
||||
/// The `MintHiveSenderToken` arm, lifted out for the same reason.
|
||||
async fn mint_hive_sender(homeserver: Option<&str>, hive: &str) -> hive_jobq::scheduler::Outcome {
|
||||
use hive_jobq::scheduler::Outcome;
|
||||
|
||||
let Some(base) = homeserver else {
|
||||
return Outcome::Failed(format!(
|
||||
"no matrix homeserver configured on this host ({} unset), so no hive \
|
||||
sender token can be minted",
|
||||
matrix_account::DEFAULT_HOMESERVER_ENV
|
||||
));
|
||||
};
|
||||
match matrix_account::hive_sender::ensure_hive_sender_token(base, hive).await {
|
||||
Ok(()) => Outcome::Done,
|
||||
Err(e) => Outcome::Failed(format!("{e:#}")),
|
||||
}
|
||||
}
|
||||
|
||||
/// Declare a brand-new agent at [`NEW_AGENT_WANTED_STATE`] — unless it turns
|
||||
/// out not to be new: an agent that already has a declaration (other than
|
||||
/// `Destroyed`, which this treats as reusable) is left alone, so a retried
|
||||
|
|
@ -2132,6 +2158,27 @@ fn queue_matrix_account_mints(
|
|||
Ok(ids)
|
||||
}
|
||||
|
||||
/// Insert one `MintHiveSenderToken` job per hive and return the nodes' ids.
|
||||
/// `matrix_account::hive_sender::spawn`'s periodic pass is the one caller.
|
||||
fn queue_hive_sender_mints(
|
||||
sched: &Mutex<hive_jobq::scheduler::Scheduler<SwarmNodeKind, SwarmResourceKind>>,
|
||||
hives: Vec<String>,
|
||||
) -> Result<Vec<hive_jobq::NodeId>> {
|
||||
let mut sched = sched
|
||||
.lock()
|
||||
.unwrap_or_else(std::sync::PoisonError::into_inner);
|
||||
let mut ids = Vec::with_capacity(hives.len());
|
||||
for hive in hives {
|
||||
let queued = sched
|
||||
.insert_job(None, |b| {
|
||||
vec![b.node(SwarmNodeKind::MintHiveSenderToken { hive }).guid()]
|
||||
})
|
||||
.map_err(|e| anyhow::anyhow!("{e}"))?;
|
||||
ids.extend(queued);
|
||||
}
|
||||
Ok(ids)
|
||||
}
|
||||
|
||||
/// The homeserver agents' own matrix accounts are minted on. Unset is this
|
||||
/// controller creating agents with no matrix account, which the mint node
|
||||
/// reports by name rather than `main` refusing to start.
|
||||
|
|
@ -2141,21 +2188,30 @@ fn configured_matrix_homeserver() -> Option<Arc<str>> {
|
|||
.map(Arc::from)
|
||||
}
|
||||
|
||||
/// Start the matrix-account backfill when a homeserver is configured. Lifted
|
||||
/// out of `main` for `clippy::too_many_lines`.
|
||||
/// Start the matrix-account backfill and the hive sender-token pass when a
|
||||
/// homeserver is configured. Lifted out of `main` for
|
||||
/// `clippy::too_many_lines`.
|
||||
fn spawn_matrix_account_backfill(
|
||||
jobq: &Arc<Mutex<hive_jobq::scheduler::Scheduler<SwarmNodeKind, SwarmResourceKind>>>,
|
||||
homeserver: Option<Arc<str>>,
|
||||
hives: &[HiveEntry],
|
||||
) {
|
||||
let Some(base) = homeserver else {
|
||||
return;
|
||||
};
|
||||
let sched = Arc::clone(jobq);
|
||||
matrix_account::agent_token::spawn(base, move |agents| {
|
||||
matrix_account::agent_token::spawn(Arc::clone(&base), move |agents| {
|
||||
if let Err(e) = queue_matrix_account_mints(&sched, agents) {
|
||||
tracing::warn!(error = %format!("{e:#}"), "agent matrix accounts: queueing failed");
|
||||
}
|
||||
});
|
||||
let sched = Arc::clone(jobq);
|
||||
let hive_names = hives.iter().map(|h| h.name.clone()).collect();
|
||||
matrix_account::hive_sender::spawn(base, hive_names, move |hives| {
|
||||
if let Err(e) = queue_hive_sender_mints(&sched, hives) {
|
||||
tracing::warn!(error = %format!("{e:#}"), "hive sender tokens: queueing failed");
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
/// Start the forge's periodic passes — the swarm-wide objects, and agents'
|
||||
|
|
@ -2714,7 +2770,8 @@ async fn main() -> Result<()> {
|
|||
hive_jobq::Graph::new(),
|
||||
hive_jobq::resources::ResourceTable::new(),
|
||||
)));
|
||||
spawn_matrix_account_backfill(&jobq, deps.matrix_homeserver.clone());
|
||||
let hives = load_hives();
|
||||
spawn_matrix_account_backfill(&jobq, deps.matrix_homeserver.clone(), &hives);
|
||||
spawn_jobq_worker(Arc::clone(&jobq), deps);
|
||||
// Bound to a named variable, not `_` — dropping the provider stops its
|
||||
// `PeriodicReader`, so it must live as long as `main` does (which it
|
||||
|
|
@ -2771,7 +2828,6 @@ async fn main() -> Result<()> {
|
|||
let config_prs = forge_client.clone().map(config_pr::spawn);
|
||||
let state_forge = keep_forge_for_state(forge_client, webhook_secret.clone());
|
||||
|
||||
let hives = load_hives();
|
||||
spawn_agent_renewal(&jobq, wanted_writer(status.as_ref()), &hives);
|
||||
// Before serving, because a hive whose role does not exist cannot log in,
|
||||
// and one whose policy does not exist logs in able to read nothing —
|
||||
|
|
@ -4370,6 +4426,37 @@ mod tests {
|
|||
assert_eq!(agents, ["a", "b"]);
|
||||
}
|
||||
|
||||
/// The hive sender-token pass's queueing: one mint node per hive, and
|
||||
/// the node names the hive rather than an agent.
|
||||
#[test]
|
||||
fn a_queued_hive_sender_mint_is_one_node_per_hive() {
|
||||
use hive_jobq_wire::WireNode as _;
|
||||
|
||||
let sched = std::sync::Mutex::new(hive_jobq::scheduler::Scheduler::new(
|
||||
hive_jobq::Graph::new(),
|
||||
hive_jobq::resources::ResourceTable::new(),
|
||||
));
|
||||
let ids =
|
||||
super::queue_hive_sender_mints(&sched, vec!["alpha".to_owned(), "beta".to_owned()])
|
||||
.expect("two jobs insert");
|
||||
assert_eq!(ids.len(), 2);
|
||||
let guard = sched
|
||||
.lock()
|
||||
.unwrap_or_else(std::sync::PoisonError::into_inner);
|
||||
let mut hives: Vec<String> = guard
|
||||
.graph()
|
||||
.nodes()
|
||||
.map(|n| {
|
||||
assert_eq!(n.payload.label(), "mint_hive_sender_token");
|
||||
let data = n.payload.data(n.id.get());
|
||||
assert!(data.get("agent").is_none(), "{data}");
|
||||
data["hive"].as_str().expect("hive is a string").to_owned()
|
||||
})
|
||||
.collect();
|
||||
hives.sort();
|
||||
assert_eq!(hives, ["alpha", "beta"]);
|
||||
}
|
||||
|
||||
/// The manual route and the periodic pass both go through
|
||||
/// `queue_forge_token_mints`, so this is the assertion that a backfilled
|
||||
/// mint is the same pair of nodes agent creation inserts: the forge user,
|
||||
|
|
|
|||
Loading…
Reference in a new issue