harness: write claude configs to systemd RuntimeDirectory + chown ~/.claude on activation (#658 fixup)

This commit is contained in:
müde 2026-05-30 22:57:26 +02:00
commit b8647cf7dc
6 changed files with 52 additions and 24 deletions

View file

@ -23,6 +23,22 @@ pub fn state_dir() -> PathBuf {
PathBuf::from(format!("/agents/{label}/state"))
}
/// Per-turn config dir for the regenerated claude-{mcp-config,settings,
/// system-prompt} files the harness drops before each turn. Set by
/// systemd via `RuntimeDirectory = "hive-config"` (#658 fixup): a
/// per-service runtime dir owned by the agent unix user, auto-cleared
/// on stop. Kept separate from `/run/hive` (the host-owned mcp.sock
/// bind) so the harness owns its own write surface and we don't have
/// to chown a bind-mounted dir. Overridable via `HYPERHIVE_CONFIG_DIR`
/// for dev / test scenarios.
#[must_use]
pub fn config_dir() -> PathBuf {
if let Some(p) = std::env::var_os("HYPERHIVE_CONFIG_DIR") {
return PathBuf::from(p);
}
PathBuf::from("/run/hive-config")
}
/// Claude credentials directory for the current agent. `$HOME/.claude`
/// matches what the `claude` CLI reads at runtime — both binaries see
/// the same `$HOME` set by the per-service systemd `environment`

View file

@ -126,9 +126,9 @@ fn parse_close_marker(line: &str) -> Option<&str> {
/// # Errors
///
/// Returns an error if the system prompt file cannot be written.
pub async fn write_system_prompt(socket: &Path, label: &str, flavor: Flavor) -> Result<PathBuf> {
let parent = socket.parent().unwrap_or_else(|| Path::new("/run/hive"));
tokio::fs::create_dir_all(parent).await.ok();
pub async fn write_system_prompt(_socket: &Path, label: &str, flavor: Flavor) -> Result<PathBuf> {
let parent = crate::paths::config_dir();
tokio::fs::create_dir_all(&parent).await.ok();
let pronouns = std::env::var("HIVE_OPERATOR_PRONOUNS").unwrap_or_else(|_| "she/her".to_owned());
let template_path = hive_sh4re::assets::prompt_template();
let template = tokio::fs::read_to_string(&template_path)

View file

@ -136,8 +136,8 @@ impl TurnFiles {
///
/// Returns an error if the config file cannot be written.
pub async fn write_mcp_config(socket: &Path) -> Result<PathBuf> {
let parent = socket.parent().unwrap_or_else(|| Path::new("/run/hive"));
tokio::fs::create_dir_all(parent).await.ok();
let parent = crate::paths::config_dir();
tokio::fs::create_dir_all(&parent).await.ok();
let path = parent.join("claude-mcp-config.json");
let exe = std::env::current_exe()
.ok()
@ -155,9 +155,9 @@ pub async fn write_mcp_config(socket: &Path) -> Result<PathBuf> {
/// # Errors
///
/// Returns an error if the settings file cannot be written.
pub async fn write_settings(socket: &Path) -> Result<PathBuf> {
let parent = socket.parent().unwrap_or_else(|| Path::new("/run/hive"));
tokio::fs::create_dir_all(parent).await.ok();
pub async fn write_settings(_socket: &Path) -> Result<PathBuf> {
let parent = crate::paths::config_dir();
tokio::fs::create_dir_all(&parent).await.ok();
let path = parent.join("claude-settings.json");
// #555: source-of-truth is `$HIVE_ASSETS_DIR/prompts/claude-settings.json`;
// copy through the per-agent runtime dir so claude reads it from the