hive-c0re: an unreadable capabilities file denies ManageRootAgent mounts
set_nspawn_flags propagated has_cap's error, so one corrupt capabilities.json failed every agent's Start, spawn and Swap. It now goes through holds_manage_root_agent, which logs the error (agent and file) and treats the capability as absent: the agent starts without the cross-agent, /applied and /meta mounts. caps_for/has_cap take the file path so that seam is testable against a tempfile. - meta.rs: a comment at the render_flake reads records why they propagate (an empty tool-groups map renders toolGroups = null, i.e. AGENT_DEFAULT, which fails open for narrower explicit entries). - capabilities::read doc: states when set_caps/remove_agent rewrite the file instead of saying remove_agent repairs it. - set/remove corrupt-file tests assert ErrorKind::InvalidData.
This commit is contained in:
parent
e0b08fe362
commit
c978060824
4 changed files with 72 additions and 17 deletions
|
|
@ -135,6 +135,24 @@ fn bind_child_agent_dirs(child: &str, binds: &mut Vec<BindMount>) {
|
|||
}
|
||||
}
|
||||
|
||||
/// Whether `agent_name` holds `ManageRootAgent` per the capabilities file
|
||||
/// at `caps_path`. An unreadable file denies: the error is logged and the
|
||||
/// agent starts without the cross-agent mounts, so one corrupt file never
|
||||
/// blocks any agent's start, spawn or swap.
|
||||
fn holds_manage_root_agent(agent_name: &str, caps_path: &Path) -> bool {
|
||||
crate::capabilities::has_cap(caps_path, agent_name, Capability::ManageRootAgent).unwrap_or_else(
|
||||
|e| {
|
||||
tracing::error!(
|
||||
agent = %agent_name,
|
||||
path = %caps_path.display(),
|
||||
error = ?e,
|
||||
"capabilities unreadable — no ManageRootAgent mounts"
|
||||
);
|
||||
false
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
/// Env var naming the host directory `swarm-bao-queue-agent.service` lands
|
||||
/// this hive's agent queue credential in. Set by the hive-c0re NixOS module
|
||||
/// from `deploy.hive-controller.queue.agentCredentialDir`; absent means this
|
||||
|
|
@ -339,7 +357,7 @@ async fn set_nspawn_flags(
|
|||
// parent field took with it the unconditional grant every
|
||||
// agent used to get over its own direct children — so an agent with
|
||||
// no capability now sees its own dirs and nothing else.
|
||||
if crate::capabilities::has_cap(agent_name, Capability::ManageRootAgent)? {
|
||||
if holds_manage_root_agent(agent_name, &crate::capabilities::capabilities_path()) {
|
||||
// Skipping self is a no-op, not a narrowing: `agent_notes_dir` is
|
||||
// `agent_state_dir/state` and `config_bind_source` is shared, so
|
||||
// binding the holder as its own virtual child reproduced the two
|
||||
|
|
@ -408,7 +426,7 @@ async fn set_nspawn_flags(
|
|||
mod tests {
|
||||
use super::{
|
||||
BindMount, QUEUE_CLIENT_ID_CREDENTIAL, QUEUE_SECRET_CREDENTIAL, bind_child_agent_dirs,
|
||||
queue_agent_credentials,
|
||||
holds_manage_root_agent, queue_agent_credentials,
|
||||
};
|
||||
|
||||
fn child_binds() -> Vec<BindMount> {
|
||||
|
|
@ -524,4 +542,23 @@ mod tests {
|
|||
]
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_corrupt_capabilities_file_denies_without_failing() {
|
||||
let dir = tempfile::tempdir().expect("tempdir");
|
||||
let path = dir.path().join("capabilities.json");
|
||||
let truncated = "{\n \"ruth\": [\"manage_root_ag";
|
||||
std::fs::write(&path, truncated).expect("seed");
|
||||
assert!(!holds_manage_root_agent("ruth", &path));
|
||||
assert_eq!(std::fs::read(&path).expect("read"), truncated.as_bytes());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_readable_grant_is_honoured() {
|
||||
let dir = tempfile::tempdir().expect("tempdir");
|
||||
let path = dir.path().join("capabilities.json");
|
||||
std::fs::write(&path, r#"{"ruth": ["manage_root_agent"]}"#).expect("seed");
|
||||
assert!(holds_manage_root_agent("ruth", &path));
|
||||
assert!(!holds_manage_root_agent("alice", &path));
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue