hive-c0re: stop minting agents' matrix accounts
The swarm mints each agent's `main` account now, so the hive's own mint goes: `ensure_user_for`, `finish_user_provisioning`, `sync_agent`, `sync_agent_standalone`, `token_path`, `legacy_password_path`, `auto_reset_password` and `token_file_present`, and the calls from the startup sweep and the rebuild bookkeeping. Both mints pinned the device `hyperhive-<agent>`, so leaving this one would have each re-login kill the other's token. `hivectl matrix create-user` refuses an agent's name and says where its account comes from. Everything that still uses the hive's appservice token stays: the hive's own account, the Space and chat room, and operator accounts.
This commit is contained in:
parent
ab153bda2f
commit
89a5dd752c
6 changed files with 61 additions and 351 deletions
|
|
@ -465,7 +465,7 @@ async fn run_swap(coord: &Arc<Coordinator>, name: &str, id: NodeId) -> Result<()
|
|||
|
||||
/// The post-`Swap` bookkeeping tail, split into its own node for dashboard
|
||||
/// visibility + retry granularity. Deps `AfterOk(Swap)`, so reaching here
|
||||
/// means the profile swap succeeded. Store/forge/matrix work only — no nix
|
||||
/// means the profile swap succeeded. Store/forge work only — no nix
|
||||
/// build (build-slot-exempt); the agent lease taken at `Swap` is still held
|
||||
/// (the whole chain up to `Reconcile` is one agent's subgraph).
|
||||
async fn run_rebuild_bookkeeping(coord: &Arc<Coordinator>, name: &str) -> Result<()> {
|
||||
|
|
@ -477,11 +477,11 @@ async fn run_rebuild_bookkeeping(coord: &Arc<Coordinator>, name: &str) -> Result
|
|||
// The `Rebuilt` manager event is emitted exactly once per agent by the DAG's
|
||||
// `EmitRebuilt` tail — emitting ok here and letting a failed tail `Reconcile`
|
||||
// add a contradictory !ok would double-report the same rebuild.
|
||||
// Full forge + matrix sync on every successful rebuild so the rebuild
|
||||
// path is equivalent to the startup sweep: tokens, config-repo mirror,
|
||||
// meta access all recover without a hive-c0re restart.
|
||||
// Full forge sync on every successful rebuild so the rebuild path is
|
||||
// equivalent to the startup sweep: tokens, config-repo mirror, meta
|
||||
// access all recover without a hive-c0re restart. (No matrix step: the
|
||||
// swarm mints an agent's matrix account, not this hive.)
|
||||
crate::forge::sync_agent(name, crate::forge::core_token().as_deref()).await;
|
||||
crate::matrix::sync_agent_standalone(name).await;
|
||||
// Wake the agent on its next turn so claude sees a "you were rebuilt"
|
||||
// hint; rescan so dashboards drop the "needs update" chip; lock bump →
|
||||
// meta-inputs re-render.
|
||||
|
|
|
|||
Loading…
Reference in a new issue