matrix: swarm-controller is the only minter
Every hive is in a swarm and every swarm runs matrix, so every swarm has a swarm-controller, and since #4810 its hive_sender pass mints each hive's @hive-<hive>: sender token into the store every five minutes. The two other minters of that token go: - swarm-matrix-ctl mint: the systemd.services.swarm-matrix-ctl unit in the hive-matrix container, Command::Mint and src/mint.rs. The binary, its appservice render/publish verbs, ctlPackage, ctlActive and the ctl cert role stay. bao-matrix-reader's checks on the deleted unit are removed; the leaf-identity and no-token-in-env checks now look at swarm-matrix-appservice-publish, which runs under the same identity. - the hive-side mint ladder in hive-c0re's ensure_hive_user (register/appservice-login/password-login with the local as_token), with read_appservice_token, paths::matrix_appservice_token and the helpers only it used. ensure_hive_user now takes the store's token, keeps the file when the store has none or can't be reached, and fails otherwise. - hivectl matrix sync-admin: the verb, HostRequest::MatrixSyncAdmin and handle_matrix_sync_admin. The periodic MatrixSweep (ensure_all) is unchanged apart from no longer reading the local as_token. This removes the double-mint race #4810's review flagged: two minters logging in on one pinned device could leave a dead token in the store until the next pass. Closes #4813 Closes #4814
This commit is contained in:
parent
91e47732a6
commit
ddb7d7196d
22 changed files with 187 additions and 1162 deletions
|
|
@ -451,14 +451,10 @@ let
|
|||
&& !(lib.hasInfix "sys/policies/acl" s);
|
||||
}
|
||||
{
|
||||
# 🩸 `read` is load-bearing here, and the publisher — the one sibling
|
||||
# that still has no `read` — shows what its absence costs. matrix-ctl's
|
||||
# first act is to read this path back and stop if something is there —
|
||||
# that read IS "and only once", so without the capability every container
|
||||
# restart would mint a second access token and invalidate the hive's.
|
||||
# (The controller holds `read` for the same idempotency reason, on the
|
||||
# agent prefix.)
|
||||
name = "matrix-ctl may read back the one path it writes";
|
||||
# 🩸 `read` is load-bearing here, unlike on the publisher: matrix-ctl's
|
||||
# `appservice publish` reads the swarm appservice token back and writes
|
||||
# only when the store's copy differs.
|
||||
name = "matrix-ctl may read back what it writes";
|
||||
ok =
|
||||
let
|
||||
s = baoGrantHere.systemd.services.swarm-bao-matrix-ctl-policy.script;
|
||||
|
|
|
|||
Loading…
Reference in a new issue