nix, hive-sh4re: name modules that exist in the stale harness-base refs

harness-base.nix has never existed in this tree. Four comments named it,
or a `harness-base` module, as the place to look:

- weston-vnc.nix: the agent user is declared and home-chowned by
  nix/agent-modules/user.nix
- hive-ci.nix: the sandbox-fallback reasoning lives in
  nix/agent-modules/default.nix -- which the very next comment block in
  the same file already cites correctly
- packages/default.nix: the per-bin consumer is
  nix/agent-modules/packages.nix
- hive-sh4re/src/assets.rs: HIVE_ASSETS_DIR is set by
  hive-c0re/environment.nix and agent-modules/default.nix +
  agent-service.nix, and the package is built by nix/packages/assets.nix
  -- not the equally nonexistent nix/assets.nix

assets.rs was twice declared out of scope on the sibling PR because it
names a module rather than a file. That distinction was real and
irrelevant: neither the module nor the nix/assets.nix path it points at
exists. Reading the wording is not checking the reference.

Every replacement path was verified to exist, with a deliberately bogus
path as a control.
This commit is contained in:
atlas 2026-08-30 03:59:53 +02:00 committed by mara
commit d17aa254dd
4 changed files with 9 additions and 7 deletions

View file

@ -3,9 +3,11 @@
//! (`hive-c0re`) and the in-container harness binaries so they agree
//! on the lookup contract.
//!
//! At runtime, the path is read from `$HIVE_ASSETS_DIR`. In nix
//! builds that env var is set by the `hive-c0re` / `harness-base` modules
//! to `${pkgs.hyperhive-assets}/share/hyperhive` (see `nix/assets.nix`).
//! At runtime, the path is read from `$HIVE_ASSETS_DIR`. In nix builds
//! that env var is set to `${pkgs.hyperhive-assets}/share/hyperhive` by
//! `nix/host-modules/hive-c0re/environment.nix` (host daemon) and
//! `nix/agent-modules/default.nix` + `agent-service.nix` (containers);
//! the package itself is built by `nix/packages/assets.nix`.
//! For `cargo run` outside nix, set it yourself:
//!
//! ```sh

View file

@ -6,7 +6,7 @@
}:
let
# GUI processes run as the agent's own non-root user — the same user
# hive-agent runs as (declared + home-chowned by harness-base.nix) — so
# hive-agent runs as (declared + home-chowned by ./user.nix) — so
# weston, the wayland client, and the agent share one user session.
# `hyperhive.user.name` is set per-agent by the meta-flake renderer.
userName = config.hyperhive.user.name;

View file

@ -280,7 +280,7 @@ in
# sandboxing always fails. Fall back to unsandboxed builds.
# Moot once every nix invocation in the container routes
# through the host daemon (the daemon governs sandboxing).
# See docs/gotchas.md and harness-base.nix.
# See docs/gotchas.md and nix/agent-modules/default.nix.
nix.settings.sandbox-fallback = lib.mkForce true;
# Degrade to a local build when a remote builder is unreachable
# rather than failing the check. `fallback` is a client-side

View file

@ -119,8 +119,8 @@ let
'';
# Per-bin split packages. Agent containers depend on the individual
# bins they actually exec/PATH-need (see harness-base.nix) instead
# of the `default` bundle — that keeps `hivectl` (dials the *host*
# bins they actually exec/PATH-need (see nix/agent-modules/packages.nix)
# instead of the `default` bundle — that keeps `hivectl` (dials the *host*
# admin socket, unreachable from inside a container, drags in
# `wireguard-tools`) and redundant binaries out of every agent's
# closure.