hive-c0re: an unreadable capabilities file denies ManageRootAgent mounts
set_nspawn_flags propagated has_cap's error, so one corrupt capabilities.json failed every agent's Start, spawn and Swap. It now goes through holds_manage_root_agent, which logs the error (agent and file) and treats the capability as absent: the agent starts without the cross-agent, /applied and /meta mounts. caps_for/has_cap take the file path so that seam is testable against a tempfile. - meta.rs: a comment at the render_flake reads records why they propagate (an empty tool-groups map renders toolGroups = null, i.e. AGENT_DEFAULT, which fails open for narrower explicit entries). - capabilities::read doc: states when set_caps/remove_agent rewrite the file instead of saying remove_agent repairs it. - set/remove corrupt-file tests assert ErrorKind::InvalidData.
This commit is contained in:
parent
e0b08fe362
commit
c978060824
4 changed files with 72 additions and 17 deletions
|
|
@ -127,15 +127,21 @@ mod tests {
|
|||
#[test]
|
||||
fn set_groups_leaves_a_corrupt_file_untouched() {
|
||||
let (_dir, path) = corrupt_file();
|
||||
set_groups_at(&path, "ruth", &["messaging".to_owned()])
|
||||
let err = set_groups_at(&path, "ruth", &["messaging".to_owned()])
|
||||
.expect_err("a corrupt file must not be overwritten");
|
||||
let kind = err
|
||||
.downcast_ref::<std::io::Error>()
|
||||
.map(std::io::Error::kind);
|
||||
assert_eq!(kind, Some(std::io::ErrorKind::InvalidData));
|
||||
assert_eq!(std::fs::read(&path).expect("read"), TRUNCATED.as_bytes());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn remove_agent_leaves_a_corrupt_file_untouched() {
|
||||
let (_dir, path) = corrupt_file();
|
||||
remove_agent_at(&path, "alice").expect_err("a corrupt file must not be overwritten");
|
||||
let err =
|
||||
remove_agent_at(&path, "alice").expect_err("a corrupt file must not be overwritten");
|
||||
assert_eq!(err.kind(), std::io::ErrorKind::InvalidData);
|
||||
assert_eq!(std::fs::read(&path).expect("read"), TRUNCATED.as_bytes());
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue