hive-c0re: an unreadable capabilities file denies ManageRootAgent mounts
set_nspawn_flags propagated has_cap's error, so one corrupt capabilities.json failed every agent's Start, spawn and Swap. It now goes through holds_manage_root_agent, which logs the error (agent and file) and treats the capability as absent: the agent starts without the cross-agent, /applied and /meta mounts. caps_for/has_cap take the file path so that seam is testable against a tempfile. - meta.rs: a comment at the render_flake reads records why they propagate (an empty tool-groups map renders toolGroups = null, i.e. AGENT_DEFAULT, which fails open for narrower explicit entries). - capabilities::read doc: states when set_caps/remove_agent rewrite the file instead of saying remove_agent repairs it. - set/remove corrupt-file tests assert ErrorKind::InvalidData.
This commit is contained in:
parent
e0b08fe362
commit
c978060824
4 changed files with 72 additions and 17 deletions
|
|
@ -1316,6 +1316,9 @@ where
|
|||
nixosConfigurations = {
|
||||
"#,
|
||||
);
|
||||
// Propagated, never read as empty: an agent with no tool-groups entry
|
||||
// renders `toolGroups = null` and gets `AGENT_DEFAULT`, which fails
|
||||
// open for any agent whose explicit entry is narrower.
|
||||
let tool_groups_map = crate::tool_groups::read()?;
|
||||
let capabilities_map = crate::capabilities::read()?;
|
||||
let resource_limits_map = crate::resource_limits::read();
|
||||
|
|
|
|||
Loading…
Reference in a new issue