docs(#2627): add READMEs for the remaining infra crates
Second increment of the per-crate README effort, covering the rest of the infra/wire/priv column: hive-priv, hive-metric, hive-types, hive-sh4re, hive-core-agent-sock, hive-agent-sock. Same shape as the first batch — purpose + when-to-use, and point at the crate-root //! docs plus the relevant docs/ pages rather than duplicating them. Wires readme = "README.md" into each Cargo.toml [package]. Disjoint from the batch-1 crates, so the two increments compose cleanly.
This commit is contained in:
parent
4017a57350
commit
bbfc578c95
12 changed files with 162 additions and 0 deletions
|
|
@ -2,6 +2,7 @@
|
|||
name = "hive-priv"
|
||||
edition.workspace = true
|
||||
version.workspace = true
|
||||
readme = "README.md"
|
||||
|
||||
[lints]
|
||||
workspace = true
|
||||
|
|
|
|||
32
hive-priv/README.md
Normal file
32
hive-priv/README.md
Normal file
|
|
@ -0,0 +1,32 @@
|
|||
# hive-priv
|
||||
|
||||
The minimal **root privileged-helper** for hive-c0re. It runs as root and
|
||||
exposes a narrow unix socket at `/run/hive/priv.sock` that accepts `PrivRequest`
|
||||
JSON lines and performs only the handful of operations that genuinely require
|
||||
root — bind-mount edits, `nsenter` into a container, btrfs subvolume ops. All
|
||||
coordination logic (broker, HTTP, scheduling) stays in the *unprivileged*
|
||||
`hive-c0re` process, which delegates here.
|
||||
|
||||
## Why it exists
|
||||
|
||||
Privsep. `hive-c0re` runs as the unprivileged `hive-core` user so a bug or a
|
||||
prompt-injection in the large daemon can't directly wield root. The few root
|
||||
operations it needs are funnelled through this small, auditable helper instead.
|
||||
See `docs/boundary.md` and `docs/security.md` for the privilege boundary.
|
||||
|
||||
## Security model
|
||||
|
||||
- **Strict allowlist.** Every request is validated against a container-name
|
||||
allowlist before any filesystem or process operation — only names matching the
|
||||
hive convention (`h-*`, the manager container, known sibling service
|
||||
containers) are accepted.
|
||||
- **No pass-through.** Every `PrivRequest` variant maps to a single known
|
||||
operation; there is no arbitrary-command escape hatch.
|
||||
- **Socket-activated, always.** systemd binds `/run/hive/priv.sock`
|
||||
(`SocketGroup=hive-core`, `0660`) and passes the listener as fd 3
|
||||
(`LISTEN_FDS`); the helper requires this and has no self-bind fallback, so dev
|
||||
and prod take the identical path and the group grant always holds.
|
||||
|
||||
The wire contract (`PrivRequest` / response types) lives in the separate
|
||||
`hive-priv-sock` crate so this root binary depends on just the protocol shapes,
|
||||
not the whole daemon-shared crate.
|
||||
Loading…
Reference in a new issue