nix/harness: ExecStartPre chown /run/hive to agent user (#658 fixup)
This commit is contained in:
parent
ed046787e0
commit
de3f541729
3 changed files with 16 additions and 12 deletions
|
|
@ -38,6 +38,14 @@ in
|
||||||
ExecStart = "${pkgs.hyperhive}/bin/hive-ag3nt serve";
|
ExecStart = "${pkgs.hyperhive}/bin/hive-ag3nt serve";
|
||||||
Restart = "on-failure";
|
Restart = "on-failure";
|
||||||
RestartSec = 2;
|
RestartSec = 2;
|
||||||
|
# `/run/hive` is bind-mounted from the host root-owned 0755
|
||||||
|
# (hive-c0re's `set_nspawn_flags`). Post-#658 the harness
|
||||||
|
# runs as the per-agent user and needs to drop mcp.sock +
|
||||||
|
# claude-{mcp-config,settings,system-prompt} files there.
|
||||||
|
# `+` runs ExecStartPre as root (before the User= drop) so
|
||||||
|
# we can chown the bind onto the agent user every start —
|
||||||
|
# robust against activation-script timing on first boot.
|
||||||
|
ExecStartPre = "+${pkgs.coreutils}/bin/chown ${userName}:${userName} /run/hive";
|
||||||
# Run the harness as the per-agent user (#658). claude itself
|
# Run the harness as the per-agent user (#658). claude itself
|
||||||
# spawned by the harness then runs as that user too — drops
|
# spawned by the harness then runs as that user too — drops
|
||||||
# root inside the container while sudo (`NOPASSWD: ALL` by
|
# root inside the container while sudo (`NOPASSWD: ALL` by
|
||||||
|
|
|
||||||
|
|
@ -687,18 +687,6 @@ in
|
||||||
[ -d "$stateDir" ] || continue
|
[ -d "$stateDir" ] || continue
|
||||||
chown -hR "$userName:$userName" "$stateDir" 2>/dev/null || true
|
chown -hR "$userName:$userName" "$stateDir" 2>/dev/null || true
|
||||||
done
|
done
|
||||||
# Same treatment for the per-agent runtime dir bind
|
|
||||||
# (`/run/hive` ← host `/run/hyperhive/{manager,agents/<n>}`,
|
|
||||||
# set by hive-c0re's `set_nspawn_flags`). Host creates it
|
|
||||||
# root:root 0755; post-#658 the harness service runs as the
|
|
||||||
# agent user and needs RW to drop `mcp.sock` and the
|
|
||||||
# claude-{mcp-config,settings,system-prompt} files there.
|
|
||||||
# Not recursive (-h still, no -R) — the dir itself is what
|
|
||||||
# the harness writes into; contents are owned by whoever
|
|
||||||
# created them at runtime.
|
|
||||||
if [ -d /run/hive ]; then
|
|
||||||
chown -h "$userName:$userName" /run/hive 2>/dev/null || true
|
|
||||||
fi
|
|
||||||
'';
|
'';
|
||||||
|
|
||||||
# Auto-inject the matrix MCP entry when matrix is enabled (#548
|
# Auto-inject the matrix MCP entry when matrix is enabled (#548
|
||||||
|
|
|
||||||
|
|
@ -48,6 +48,14 @@ in
|
||||||
ExecStart = "${pkgs.hyperhive}/bin/hive-m1nd serve";
|
ExecStart = "${pkgs.hyperhive}/bin/hive-m1nd serve";
|
||||||
Restart = "on-failure";
|
Restart = "on-failure";
|
||||||
RestartSec = 2;
|
RestartSec = 2;
|
||||||
|
# `/run/hive` is bind-mounted from the host root-owned 0755
|
||||||
|
# (hive-c0re's `set_nspawn_flags`). Post-#658 the harness
|
||||||
|
# runs as the per-agent user and needs to drop mcp.sock +
|
||||||
|
# claude-{mcp-config,settings,system-prompt} files there.
|
||||||
|
# `+` runs ExecStartPre as root (before the User= drop) so
|
||||||
|
# we can chown the bind onto the agent user every start —
|
||||||
|
# robust against activation-script timing on first boot.
|
||||||
|
ExecStartPre = "+${pkgs.coreutils}/bin/chown ${userName}:${userName} /run/hive";
|
||||||
# Same drop-from-root as agent-base.nix (#658). Manager
|
# Same drop-from-root as agent-base.nix (#658). Manager
|
||||||
# interactions with the host (rebuild approvals, config
|
# interactions with the host (rebuild approvals, config
|
||||||
# writes) still happen via the dedicated unix sockets
|
# writes) still happen via the dedicated unix sockets
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue