fix(#2368): AGENT_RUNTIME_ROOT → priv_proto; fix stale priv comment; cross-ref lockstep
- Add `priv_proto::AGENT_RUNTIME_ROOT` to hive-sh4re as the shared
single source for the per-agent runtime root path. hive-priv now
imports it instead of carrying a local const with a stale comment
that still pointed at `coordinator::AGENT_RUNTIME_ROOT` (removed in
#2285/#2367 — moved to `paths::agent_runtime_root()`).
- Add 'must stay in sync' cross-ref comments on both sides of the
privsep boundary:
· priv_proto::META_DIR ↔ paths::meta_root()
· priv_proto::AGENT_STATE_ROOT ↔ paths::AGENTS_ROOT
· priv_proto::AGENT_RUNTIME_ROOT ↔ paths::RUNTIME_ROOT + agent_runtime_root()
· paths::AGENTS_ROOT ↔ priv_proto::AGENT_STATE_ROOT
· paths::RUNTIME_ROOT ↔ priv_proto::AGENT_RUNTIME_ROOT
The dep graph prevents a shared import (hive-sh4re is a leaf; both
hive-c0re and hive-priv depend on it but not each other), so the
lockstep comments are the enforced contract.
This commit is contained in:
parent
4745274fca
commit
dcd559e7c7
3 changed files with 19 additions and 7 deletions
|
|
@ -31,6 +31,8 @@ pub const STATE_ROOT: &str = "/var/lib/hyperhive";
|
||||||
/// `/run/hyperhive` — hive-c0re's runtime root (host admin socket, the
|
/// `/run/hyperhive` — hive-c0re's runtime root (host admin socket, the
|
||||||
/// per-agent runtime dirs). Regenerated each boot; not persistent state.
|
/// per-agent runtime dirs). Regenerated each boot; not persistent state.
|
||||||
// nix: `RuntimeDirectory=hyperhive` on the hive-c0re service (hive-c0re.nix) — must match.
|
// nix: `RuntimeDirectory=hyperhive` on the hive-c0re service (hive-c0re.nix) — must match.
|
||||||
|
// sh4re: `hive_sh4re::priv_proto::AGENT_RUNTIME_ROOT` is `RUNTIME_ROOT + "/agents"` and must
|
||||||
|
// stay in sync; the privsep boundary prevents importing across the crate.
|
||||||
pub const RUNTIME_ROOT: &str = "/run/hyperhive";
|
pub const RUNTIME_ROOT: &str = "/run/hyperhive";
|
||||||
|
|
||||||
/// Default host admin socket (`/run/hyperhive/host.sock`). Exposed as a
|
/// Default host admin socket (`/run/hyperhive/host.sock`). Exposed as a
|
||||||
|
|
@ -152,6 +154,8 @@ pub fn agent_sockets_file() -> PathBuf {
|
||||||
/// dashboard state-file allow-list uses it for `strip_prefix` /
|
/// dashboard state-file allow-list uses it for `strip_prefix` /
|
||||||
/// `starts_with` checks), so it stays a const; [`agents_root`] wraps it.
|
/// `starts_with` checks), so it stays a const; [`agents_root`] wraps it.
|
||||||
// nix: agent container bind-mount source (harness-base.nix / agent-base.nix) — must match.
|
// nix: agent container bind-mount source (harness-base.nix / agent-base.nix) — must match.
|
||||||
|
// sh4re: `hive_sh4re::priv_proto::AGENT_STATE_ROOT` is the same value and must stay in sync;
|
||||||
|
// the privsep boundary prevents importing across the crate.
|
||||||
pub const AGENTS_ROOT: &str = "/var/lib/hyperhive/agents";
|
pub const AGENTS_ROOT: &str = "/var/lib/hyperhive/agents";
|
||||||
|
|
||||||
#[must_use]
|
#[must_use]
|
||||||
|
|
|
||||||
|
|
@ -21,9 +21,9 @@ use std::path::{Path, PathBuf};
|
||||||
|
|
||||||
use anyhow::{Context as _, Result, bail};
|
use anyhow::{Context as _, Result, bail};
|
||||||
use hive_sh4re::priv_proto::{
|
use hive_sh4re::priv_proto::{
|
||||||
AGENT_PREFIX, AGENT_STATE_ROOT, BindMount, CredentialMount, InfraAction, InfraContainer,
|
AGENT_PREFIX, AGENT_RUNTIME_ROOT, AGENT_STATE_ROOT, BindMount, CredentialMount, InfraAction,
|
||||||
JournalQuery, META_DIR, NetworkIsolation, PRIV_SOCK, PrivEvent, PrivRequest, PrivResponse,
|
InfraContainer, JournalQuery, META_DIR, NetworkIsolation, PRIV_SOCK, PrivEvent, PrivRequest,
|
||||||
PrivStream, PrivStreamLine, SIBLING_CONTAINERS,
|
PrivResponse, PrivStream, PrivStreamLine, SIBLING_CONTAINERS,
|
||||||
};
|
};
|
||||||
use tokio::io::{AsyncBufReadExt, AsyncWriteExt, BufReader};
|
use tokio::io::{AsyncBufReadExt, AsyncWriteExt, BufReader};
|
||||||
use tokio::net::unix::OwnedWriteHalf;
|
use tokio::net::unix::OwnedWriteHalf;
|
||||||
|
|
@ -33,10 +33,6 @@ use tokio::process::Command;
|
||||||
/// Root of the per-agent unix-socket dirs on the host.
|
/// Root of the per-agent unix-socket dirs on the host.
|
||||||
const SOCKET_DIR_ROOT: &str = "/run/hive-agent";
|
const SOCKET_DIR_ROOT: &str = "/run/hive-agent";
|
||||||
|
|
||||||
/// Root of the per-agent MCP socket dirs on the host.
|
|
||||||
/// Matches `coordinator::AGENT_RUNTIME_ROOT` in hive-c0re.
|
|
||||||
const AGENT_RUNTIME_ROOT: &str = "/run/hyperhive/agents";
|
|
||||||
|
|
||||||
#[tokio::main]
|
#[tokio::main]
|
||||||
async fn main() -> Result<()> {
|
async fn main() -> Result<()> {
|
||||||
tracing_subscriber::fmt()
|
tracing_subscriber::fmt()
|
||||||
|
|
|
||||||
|
|
@ -101,14 +101,26 @@ impl std::str::FromStr for InfraContainer {
|
||||||
|
|
||||||
/// Host path of the meta flake. The flake ref for agent `<name>` is
|
/// Host path of the meta flake. The flake ref for agent `<name>` is
|
||||||
/// `{META_DIR}#{name}`, derived by `hive-priv` — never passed over the wire.
|
/// `{META_DIR}#{name}`, derived by `hive-priv` — never passed over the wire.
|
||||||
|
/// Must stay in sync with `hive-c0re::paths::meta_root()` (`STATE_ROOT +
|
||||||
|
/// "/meta"`); the privsep boundary prevents importing across the crate.
|
||||||
pub const META_DIR: &str = "/var/lib/hyperhive/meta";
|
pub const META_DIR: &str = "/var/lib/hyperhive/meta";
|
||||||
|
|
||||||
/// Root of per-agent state directories on the host.
|
/// Root of per-agent state directories on the host.
|
||||||
/// Subdirectory layout: `<AGENT_STATE_ROOT>/<name>/state/<file>`.
|
/// Subdirectory layout: `<AGENT_STATE_ROOT>/<name>/state/<file>`.
|
||||||
/// Used by `WriteAgentStateFile` to derive the write path so the
|
/// Used by `WriteAgentStateFile` to derive the write path so the
|
||||||
/// exact path is never passed over the wire.
|
/// exact path is never passed over the wire.
|
||||||
|
/// Must stay in sync with `hive-c0re::paths::AGENTS_ROOT`; the privsep
|
||||||
|
/// boundary prevents importing across the crate.
|
||||||
pub const AGENT_STATE_ROOT: &str = "/var/lib/hyperhive/agents";
|
pub const AGENT_STATE_ROOT: &str = "/var/lib/hyperhive/agents";
|
||||||
|
|
||||||
|
/// Root of per-agent runtime directories on the host (regenerated each boot
|
||||||
|
/// by `hive-priv` tmpfiles.d; not persistent). Used by `hive-priv` when
|
||||||
|
/// creating per-agent subdirs via `nsenter` / tmpfiles.
|
||||||
|
/// Must stay in sync with `hive-c0re::paths::agent_runtime_root()`
|
||||||
|
/// (`RUNTIME_ROOT + "/agents"`); the privsep boundary prevents importing
|
||||||
|
/// across the crate.
|
||||||
|
pub const AGENT_RUNTIME_ROOT: &str = "/run/hyperhive/agents";
|
||||||
|
|
||||||
/// Output format for `ReadContainerJournal`. Maps to journalctl
|
/// Output format for `ReadContainerJournal`. Maps to journalctl
|
||||||
/// `--output=<...>`. Restricted to the two formats hive callers use so
|
/// `--output=<...>`. Restricted to the two formats hive callers use so
|
||||||
/// the wire type can't smuggle an arbitrary `--output` value.
|
/// the wire type can't smuggle an arbitrary `--output` value.
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue