Watch
0
0
Fork
You've already forked hyperhive
0

hive-c0re: an unreadable capabilities file denies ManageRootAgent mounts

set_nspawn_flags propagated has_cap's error, so one corrupt
capabilities.json failed every agent's Start, spawn and Swap. It now
goes through holds_manage_root_agent, which logs the error (agent and
file) and treats the capability as absent: the agent starts without the
cross-agent, /applied and /meta mounts. caps_for/has_cap take the file
path so that seam is testable against a tempfile.

- meta.rs: a comment at the render_flake reads records why they
  propagate (an empty tool-groups map renders toolGroups = null, i.e.
  AGENT_DEFAULT, which fails open for narrower explicit entries).
- capabilities::read doc: states when set_caps/remove_agent rewrite
  the file instead of saying remove_agent repairs it.
- set/remove corrupt-file tests assert ErrorKind::InvalidData.
This commit is contained in:
atlas 2026-09-26 14:43:53 +02:00 • committed by mara
commit c978060824
4 changed files with 72 additions and 17 deletions

View file

@ -1316,6 +1316,9 @@ where
nixosConfigurations = {
"#,
);
// Propagated, never read as empty: an agent with no tool-groups entry
// renders `toolGroups = null` and gets `AGENT_DEFAULT`, which fails
// open for any agent whose explicit entry is narrower.
let tool_groups_map = crate::tool_groups::read()?;
let capabilities_map = crate::capabilities::read()?;
let resource_limits_map = crate::resource_limits::read();