Watch
0
0
Fork
You've already forked hyperhive
0

swarm-controller: mint each hive's matrix sender token

A hive whose homeserver runs on another host has no local
matrix-appservice-token, so hive-c0re's matrix sweep returned before
reaching the store read in ensure_hive_user: no @hive-<name>: token, no
Space, no chat room, no invites, and a sweep-health banner.

swarm-controller now mints @hive-<name>: with the swarm appservice
token for every hive in its directory, as a MintHiveSenderToken job
node queued by a five-minute pass, and stores it at
swarm/hives/<name>/matrix/sender-token, the same matrix::Credential
swarm-matrix-ctl writes there. It is keep-if-live, reusing agent_token's
classify/plan: a stored token whoami confirms as @hive-<name>: is left
alone, so only an absent or dead one is minted. agent_token's probe and
mint steps are lifted into probe_at/mint_at so both passes share them.

swarm-matrix-ctl mint still writes the path for its own hive when it is
empty. If both mint an empty path at once, one token is invalidated
(same pinned device); the next pass classifies it Revoked and re-mints.

hive-c0re's ensure_all no longer returns when there is no local
as_token. ensure_hive_user reads the store first on every sweep and
overwrites its token file when the store's token differs, keeps the
file when the store has none, mints with the local as_token only when
neither holds one, and fails with one error when there is nothing at
all. The decision is sender_source, unit-tested.

The controller's bao policy gains create/read/update on
swarm/hives/+/matrix/sender-token (`+`, since `*` is a glob only at the
end of a path), pinned in module-eval.

Refs #4427
This commit is contained in:
atlas 2026-09-29 20:18:11 +02:00 • committed by mara
commit 78d8d69c7f
10 changed files with 504 additions and 80 deletions

View file

@ -107,7 +107,7 @@ pub fn plan(observed: &[(String, Observed)]) -> Vec<String> {
}
/// The swarm appservice token, or an error naming why there is none.
async fn appservice_token(store: &SecretStore) -> Result<String> {
pub(super) async fn appservice_token(store: &SecretStore) -> Result<String> {
let path = matrix::swarm_appservice_token_path()?;
let stored: Option<matrix::Credential> = store
.read_optional(&path)
@ -129,9 +129,18 @@ async fn probe(
base: &str,
agent: &str,
) -> Result<Probe> {
let path = matrix::account_path(agent, ACCOUNT)?;
probe_at(store, http, base, &matrix::account_path(agent, ACCOUNT)?).await
}
/// What the store and the homeserver say about the token stored at `path`.
pub(super) async fn probe_at(
store: &SecretStore,
http: &reqwest::Client,
base: &str,
path: &str,
) -> Result<Probe> {
let stored: Option<matrix::Credential> = store
.read_optional(&path)
.read_optional(path)
.await
.with_context(|| format!("reading {path}"))?;
let Some(stored) = stored else {
@ -170,35 +179,52 @@ pub async fn ensure_agent_matrix_account(base: &str, agent: &str) -> Result<()>
Decision::Mint(reason) => reason,
};
let token = match homeserver::register(&http, base, agent, &as_token).await? {
let path = matrix::account_path(agent, ACCOUNT)?;
mint_at(&store, &http, base, agent, &as_token, &path).await?;
tracing::info!(agent, ?reason, %path, "agent matrix account token minted and stored");
Ok(())
}
/// Create the account `account` (a localpart), or log in to it as the appservice when it
/// exists, store the token at `path`, and read it back with `whoami`.
///
/// # Errors
/// When the store or the homeserver refuses a step, or the new token
/// authenticates as someone else.
pub(super) async fn mint_at(
store: &SecretStore,
http: &reqwest::Client,
base: &str,
account: &str,
as_token: &str,
path: &str,
) -> Result<()> {
let token = match homeserver::register(http, base, account, as_token).await? {
homeserver::Registered::Token(token) => token,
// An agent minted before, or one a hive created back when hives did
// this: log in as the appservice on the same device instead.
// An account minted before, or one a hive created itself: log in as
// the appservice on the same device instead.
homeserver::Registered::AlreadyExists => {
homeserver::appservice_login(&http, base, agent, &as_token).await?
homeserver::appservice_login(http, base, account, as_token).await?
}
};
let path = matrix::account_path(agent, ACCOUNT)?;
store
.write(
&path,
path,
&matrix::Credential {
value: token.clone(),
homeserver: Some(base.to_owned()),
},
)
.await
.with_context(|| format!("storing {agent}'s matrix token at {path}"))?;
.with_context(|| format!("storing @{account}'s matrix token at {path}"))?;
match homeserver::whoami(&http, base, &token)
match homeserver::whoami(http, base, &token)
.await
.with_context(|| format!("using {agent}'s new matrix token"))?
.with_context(|| format!("using @{account}'s new matrix token"))?
{
Whoami::User(user) if localpart(&user) == Some(agent) => {}
_ => bail!("{agent}'s new matrix token does not authenticate as {agent}"),
Whoami::User(user) if localpart(&user) == Some(account) => Ok(()),
_ => bail!("@{account}'s new matrix token does not authenticate as @{account}"),
}
tracing::info!(agent, ?reason, %path, "agent matrix account token minted and stored");
Ok(())
}
/// One pass: every agent holding a store identity, observed.

View file

@ -0,0 +1,201 @@
//! Each hive's sender account, `@hive-<hive>:`, on the swarm's homeserver:
//! created here with the **swarm's** appservice token and stored at
//! `swarm/hives/<hive>/matrix/sender-token`, where hive-c0re's matrix sweep
//! reads it under the hive's own store identity. A hive whose homeserver runs
//! elsewhere holds no appservice token, so this is its only sender token.
//!
//! Runs for every hive in the directory, local or remote, and decides the
//! same way [`super::agent_token`] does: a stored token that `whoami`
//! confirms as `@hive-<hive>:` is kept, so this writes only when the path is
//! empty or its token is dead.
//!
//! ⚠️ `swarm-matrix-ctl mint` also writes this path for the hive whose host
//! runs the homeserver, and skips when it is non-empty. Both log in on the
//! same pinned device, so if both find it empty at once, one of the two
//! tokens is dead on arrival. Whichever of them lands in the store, the next
//! [`RECONCILE_INTERVAL`] pass either keeps it (live) or re-mints it
//! (`Revoked`), and matrix-ctl never writes a non-empty path — so the store
//! converges on one live token, and the hive's sweep takes whatever it holds.
use std::sync::Arc;
use anyhow::{Context, Result};
use swarm_matrix_client as homeserver;
use swarm_secret_client::matrix;
use super::agent_token::{Decision, Observed, appservice_token, classify, mint_at, plan, probe_at};
/// How often [`spawn`] re-checks every hive's sender token.
const RECONCILE_INTERVAL: std::time::Duration = std::time::Duration::from_mins(5);
/// Decide what to do about `hive`'s sender token from what the stored one is.
fn classify_hive(hive: &str, probe: &super::agent_token::Probe) -> Decision {
classify(&matrix::hive_localpart(hive), probe)
}
/// Make sure `hive`'s sender account holds a live token in the store,
/// creating the account or logging in to it when it does not. The whole job
/// of the `MintHiveSenderToken` node.
///
/// # Errors
/// When the store or the homeserver refuses a step, the swarm appservice
/// token has not been published, or the new token authenticates as someone
/// else.
pub async fn ensure_hive_sender_token(base: &str, hive: &str) -> Result<()> {
let store = crate::store::connect()
.await
.context("logging in to the swarm secret store")?;
let as_token = appservice_token(&store).await?;
let http = homeserver::client()?;
let path = matrix::sender_token_path(hive)?;
let reason = match classify_hive(hive, &probe_at(&store, &http, base, &path).await?) {
Decision::Keep => {
tracing::debug!(hive, "hive sender token is current; left as it is");
return Ok(());
}
Decision::Mint(reason) => reason,
};
let localpart = matrix::hive_localpart(hive);
mint_at(&store, &http, base, &localpart, &as_token, &path).await?;
tracing::info!(hive, ?reason, %path, "hive sender token minted and stored");
Ok(())
}
/// One pass: every hive in `hives`, observed.
///
/// Fails as a whole when the swarm appservice token is not published, for
/// the reason `agent_token`'s pass does.
async fn observe_all(base: &str, hives: &[String]) -> Result<Vec<(String, Observed)>> {
let store = crate::store::connect()
.await
.context("logging in to the swarm secret store")?;
appservice_token(&store).await?;
let http = homeserver::client()?;
let mut observed = Vec::with_capacity(hives.len());
for hive in hives {
let o = match matrix::sender_token_path(hive) {
Ok(path) => match probe_at(&store, &http, base, &path).await {
Ok(p) => Observed::Decided(classify_hive(hive, &p)),
Err(e) => {
tracing::warn!(hive, error = %format!("{e:#}"), "hive sender token: read failed");
Observed::Unknown
}
},
Err(e) => {
tracing::warn!(hive, error = %e, "hive sender token: the hive name forms no store path");
Observed::Unknown
}
};
observed.push((hive.clone(), o));
}
Ok(observed)
}
/// Check every hive's sender token now and every [`RECONCILE_INTERVAL`]
/// after, and hand the hives that need one to `enqueue`, which inserts a
/// `MintHiveSenderToken` node for each.
///
/// The roster is the controller's hive directory. A pass that fails is
/// logged and retried on the next tick; it never stops the daemon.
pub fn spawn(base: Arc<str>, hives: Vec<String>, enqueue: impl Fn(Vec<String>) + Send + 'static) {
tokio::spawn(async move {
let mut ticker = tokio::time::interval(RECONCILE_INTERVAL);
loop {
ticker.tick().await;
match observe_all(&base, &hives).await {
Ok(observed) => {
let minting = plan(&observed);
if minting.is_empty() {
tracing::debug!(
checked = observed.len(),
"hive sender tokens: all current"
);
} else {
tracing::info!(
checked = observed.len(),
minting = minting.len(),
"hive sender tokens: queueing mints"
);
enqueue(minting);
}
}
Err(e) => tracing::warn!(
error = %format!("{e:#}"),
retry_in_s = RECONCILE_INTERVAL.as_secs(),
"hive sender tokens: pass failed; retrying next tick"
),
}
}
});
}
#[cfg(test)]
mod tests {
use super::super::agent_token::{MintReason, Probe};
use super::*;
use swarm_matrix_client::Whoami;
fn user(id: &str) -> Probe {
Probe::Whoami(Whoami::User(id.to_owned()))
}
#[test]
fn a_live_token_for_the_hive_account_is_kept() {
assert_eq!(
classify_hive("pr1ma", &user("@hive-pr1ma:t.local")),
Decision::Keep
);
}
#[test]
fn nothing_stored_mints() {
// A hive whose homeserver is remote: nothing has ever written its path.
assert_eq!(
classify_hive("pr1ma", &Probe::NotStored),
Decision::Mint(MintReason::NotStored)
);
}
#[test]
fn a_dead_token_mints() {
// What the loser of a simultaneous mint with matrix-ctl leaves behind.
assert_eq!(
classify_hive("pr1ma", &Probe::Whoami(Whoami::UnknownToken)),
Decision::Mint(MintReason::Revoked)
);
}
#[test]
fn a_token_for_another_account_mints() {
// The bare hive name is an agent's localpart, not the hive's account,
// and another hive's account is not this one's.
for other in ["@pr1ma:t.local", "@hive-beta:t.local", "@hive:t.local"] {
assert_eq!(
classify_hive("pr1ma", &user(other)),
Decision::Mint(MintReason::OtherUser),
"{other}"
);
}
}
#[test]
fn an_outage_plans_nothing() {
// A mint replaces the token the hive is running on, so a pass that
// could not read must not mint for every hive.
let observed = [
("alpha".to_owned(), Observed::Unknown),
("beta".to_owned(), Observed::Unknown),
];
assert!(plan(&observed).is_empty());
}
#[test]
fn the_published_path_is_the_one_the_hive_reads() {
// hive-c0re's `stored_sender_token` and `swarm-matrix-ctl mint` both
// resolve this path; the literal is what the bao grant names.
assert_eq!(
matrix::sender_token_path("pr1ma").expect("a plain name is legal"),
"swarm/hives/pr1ma/matrix/sender-token"
);
}
}