matrix: swarm-controller is the only minter
Every hive is in a swarm and every swarm runs matrix, so every swarm has a swarm-controller, and since #4810 its hive_sender pass mints each hive's @hive-<hive>: sender token into the store every five minutes. The two other minters of that token go: - swarm-matrix-ctl mint: the systemd.services.swarm-matrix-ctl unit in the hive-matrix container, Command::Mint and src/mint.rs. The binary, its appservice render/publish verbs, ctlPackage, ctlActive and the ctl cert role stay. bao-matrix-reader's checks on the deleted unit are removed; the leaf-identity and no-token-in-env checks now look at swarm-matrix-appservice-publish, which runs under the same identity. - the hive-side mint ladder in hive-c0re's ensure_hive_user (register/appservice-login/password-login with the local as_token), with read_appservice_token, paths::matrix_appservice_token and the helpers only it used. ensure_hive_user now takes the store's token, keeps the file when the store has none or can't be reached, and fails otherwise. - hivectl matrix sync-admin: the verb, HostRequest::MatrixSyncAdmin and handle_matrix_sync_admin. The periodic MatrixSweep (ensure_all) is unchanged apart from no longer reading the local as_token. This removes the double-mint race #4810's review flagged: two minters logging in on one pinned device could leave a dead token in the store until the next pass. Closes #4813 Closes #4814
This commit is contained in:
parent
91e47732a6
commit
ddb7d7196d
22 changed files with 187 additions and 1162 deletions
|
|
@ -36,11 +36,11 @@ pub enum Cmd {
|
|||
#[command(subcommand)]
|
||||
cmd: ForgeCmd,
|
||||
},
|
||||
/// matrix-tuwunel user provisioning.
|
||||
/// matrix-tuwunel invites.
|
||||
///
|
||||
/// Manual entry point to the same idempotent provisioning c0re runs at
|
||||
/// boot — for re-registering an agent the boot sweep skipped, or after
|
||||
/// wiping a token file.
|
||||
/// Manual invites into the hive Space and its rooms; c0re's periodic
|
||||
/// matrix sweep provisions the Space, the chat room and the agents'
|
||||
/// invites on its own.
|
||||
Matrix {
|
||||
#[command(subcommand)]
|
||||
cmd: MatrixCmd,
|
||||
|
|
@ -286,11 +286,6 @@ impl From<ReconcileFrom> for hive_host_sock::ReconcileDirection {
|
|||
|
||||
#[derive(Subcommand)]
|
||||
pub enum MatrixCmd {
|
||||
/// Provision (or re-provision) the matrix appservice's sender account.
|
||||
///
|
||||
/// Runs automatically on startup; run manually to recover a missing
|
||||
/// access token.
|
||||
SyncAdmin,
|
||||
/// Invite a matrix user to the hive Space, or a specific room with
|
||||
/// `--room`. Idempotent.
|
||||
Invite {
|
||||
|
|
|
|||
|
|
@ -1,7 +1,6 @@
|
|||
//! `hivectl matrix` — matrix account provisioning verbs. hivectl forwards
|
||||
//! each request to the daemon (which owns the register + sender tokens and
|
||||
//! the matrix creds dir) and renders the reply; it no longer links the
|
||||
//! matrix machinery itself.
|
||||
//! `hivectl matrix` — matrix provisioning verbs. hivectl forwards
|
||||
//! each request to the daemon (which owns the sender token) and renders the
|
||||
//! reply; it no longer links the matrix machinery itself.
|
||||
|
||||
use std::path::Path;
|
||||
|
||||
|
|
@ -13,15 +12,14 @@ use crate::cli::MatrixCmd;
|
|||
/// dispatch match so the top-level router stays small.
|
||||
pub(crate) async fn run_matrix_cmd(socket: &Path, cmd: MatrixCmd) -> Result<()> {
|
||||
match cmd {
|
||||
MatrixCmd::SyncAdmin => matrix_sync_admin(socket).await,
|
||||
MatrixCmd::Invite { user, room } => matrix_invite(socket, &user, room.as_deref()).await,
|
||||
}
|
||||
}
|
||||
|
||||
/// Send a matrix provisioning request to the daemon and print the
|
||||
/// operator-facing result lines it returns. The daemon owns the register +
|
||||
/// sender tokens and the matrix creds dir, so hivectl no longer links the
|
||||
/// matrix machinery — it just forwards the request and renders the reply.
|
||||
/// operator-facing result lines it returns. The daemon owns the sender token,
|
||||
/// so hivectl no longer links the matrix machinery — it just forwards the
|
||||
/// request and renders the reply.
|
||||
async fn matrix_request(socket: &Path, req: hive_host_sock::HostRequest) -> Result<()> {
|
||||
let resp = crate::client::request(socket, req)
|
||||
.await
|
||||
|
|
@ -38,10 +36,6 @@ async fn matrix_request(socket: &Path, req: hive_host_sock::HostRequest) -> Resu
|
|||
Ok(())
|
||||
}
|
||||
|
||||
async fn matrix_sync_admin(socket: &Path) -> Result<()> {
|
||||
matrix_request(socket, hive_host_sock::HostRequest::MatrixSyncAdmin).await
|
||||
}
|
||||
|
||||
async fn matrix_invite(socket: &Path, user: &str, room: Option<&str>) -> Result<()> {
|
||||
matrix_request(
|
||||
socket,
|
||||
|
|
|
|||
Loading…
Reference in a new issue