diff --git a/hive-c0re/src/paths.rs b/hive-c0re/src/paths.rs index ee3bb0b0..cbcf1a7e 100644 --- a/hive-c0re/src/paths.rs +++ b/hive-c0re/src/paths.rs @@ -31,6 +31,8 @@ pub const STATE_ROOT: &str = "/var/lib/hyperhive"; /// `/run/hyperhive` — hive-c0re's runtime root (host admin socket, the /// per-agent runtime dirs). Regenerated each boot; not persistent state. // nix: `RuntimeDirectory=hyperhive` on the hive-c0re service (hive-c0re.nix) — must match. +// sh4re: `hive_sh4re::priv_proto::AGENT_RUNTIME_ROOT` is `RUNTIME_ROOT + "/agents"` and must +// stay in sync; the privsep boundary prevents importing across the crate. pub const RUNTIME_ROOT: &str = "/run/hyperhive"; /// Default host admin socket (`/run/hyperhive/host.sock`). Exposed as a @@ -152,6 +154,8 @@ pub fn agent_sockets_file() -> PathBuf { /// dashboard state-file allow-list uses it for `strip_prefix` / /// `starts_with` checks), so it stays a const; [`agents_root`] wraps it. // nix: agent container bind-mount source (harness-base.nix / agent-base.nix) — must match. +// sh4re: `hive_sh4re::priv_proto::AGENT_STATE_ROOT` is the same value and must stay in sync; +// the privsep boundary prevents importing across the crate. pub const AGENTS_ROOT: &str = "/var/lib/hyperhive/agents"; #[must_use] diff --git a/hive-priv/src/main.rs b/hive-priv/src/main.rs index 615e0794..93293183 100644 --- a/hive-priv/src/main.rs +++ b/hive-priv/src/main.rs @@ -21,9 +21,9 @@ use std::path::{Path, PathBuf}; use anyhow::{Context as _, Result, bail}; use hive_sh4re::priv_proto::{ - AGENT_PREFIX, AGENT_STATE_ROOT, BindMount, CredentialMount, InfraAction, InfraContainer, - JournalQuery, META_DIR, NetworkIsolation, PRIV_SOCK, PrivEvent, PrivRequest, PrivResponse, - PrivStream, PrivStreamLine, SIBLING_CONTAINERS, + AGENT_PREFIX, AGENT_RUNTIME_ROOT, AGENT_STATE_ROOT, BindMount, CredentialMount, InfraAction, + InfraContainer, JournalQuery, META_DIR, NetworkIsolation, PRIV_SOCK, PrivEvent, PrivRequest, + PrivResponse, PrivStream, PrivStreamLine, SIBLING_CONTAINERS, }; use tokio::io::{AsyncBufReadExt, AsyncWriteExt, BufReader}; use tokio::net::unix::OwnedWriteHalf; @@ -33,10 +33,6 @@ use tokio::process::Command; /// Root of the per-agent unix-socket dirs on the host. const SOCKET_DIR_ROOT: &str = "/run/hive-agent"; -/// Root of the per-agent MCP socket dirs on the host. -/// Matches `coordinator::AGENT_RUNTIME_ROOT` in hive-c0re. -const AGENT_RUNTIME_ROOT: &str = "/run/hyperhive/agents"; - #[tokio::main] async fn main() -> Result<()> { tracing_subscriber::fmt() diff --git a/hive-sh4re/src/priv_proto.rs b/hive-sh4re/src/priv_proto.rs index 5ca0268e..89fef768 100644 --- a/hive-sh4re/src/priv_proto.rs +++ b/hive-sh4re/src/priv_proto.rs @@ -101,14 +101,26 @@ impl std::str::FromStr for InfraContainer { /// Host path of the meta flake. The flake ref for agent `` is /// `{META_DIR}#{name}`, derived by `hive-priv` — never passed over the wire. +/// Must stay in sync with `hive-c0re::paths::meta_root()` (`STATE_ROOT + +/// "/meta"`); the privsep boundary prevents importing across the crate. pub const META_DIR: &str = "/var/lib/hyperhive/meta"; /// Root of per-agent state directories on the host. /// Subdirectory layout: `//state/`. /// Used by `WriteAgentStateFile` to derive the write path so the /// exact path is never passed over the wire. +/// Must stay in sync with `hive-c0re::paths::AGENTS_ROOT`; the privsep +/// boundary prevents importing across the crate. pub const AGENT_STATE_ROOT: &str = "/var/lib/hyperhive/agents"; +/// Root of per-agent runtime directories on the host (regenerated each boot +/// by `hive-priv` tmpfiles.d; not persistent). Used by `hive-priv` when +/// creating per-agent subdirs via `nsenter` / tmpfiles. +/// Must stay in sync with `hive-c0re::paths::agent_runtime_root()` +/// (`RUNTIME_ROOT + "/agents"`); the privsep boundary prevents importing +/// across the crate. +pub const AGENT_RUNTIME_ROOT: &str = "/run/hyperhive/agents"; + /// Output format for `ReadContainerJournal`. Maps to journalctl /// `--output=<...>`. Restricted to the two formats hive callers use so /// the wire type can't smuggle an arbitrary `--output` value.