swarm: let an agent publish its own icon
The auth callout grants an agent that presents its own queue credential one more subject, `$KV.agent-icons.<agent>`: its own key in the agent-icons bucket and no other. The hive's shared agent client is granted none of the bucket, since every agent on a hive presents it. hive-agent writes `/etc/hyperhive/icon.svg`, the file its `GET /icon` serves, to that key once per start, as a JetStream publish straight to the subject (what `kv::Store::put` sends, minus the bucket lookup), so the one subject is the whole grant. No icon deletes the key. A failed write, including one that arrives before the bucket exists, is retried with backoff until acked. An agent connected with the hive's shared client publishes nothing. swarm-controller creates the bucket as soon as its queue connection is up, instead of on the first icon read, so an agent's write does not wait for someone to look. Measured against a local nats-server with a user allowed publish on `$KV.agent-icons.atlas` only: the write to its own key is stored and readable, a write to `$KV.agent-icons.argus` is refused (the ack times out), the DEL marker makes the key read as absent, and a write before the bucket exists fails with "no responders".
This commit is contained in:
parent
4dbab024da
commit
e974194e3a
13 changed files with 348 additions and 27 deletions
|
|
@ -946,10 +946,15 @@ fn agent_status_reader(
|
|||
/// same rationale as [`wanted_writer`]. No staleness threshold, unlike
|
||||
/// [`agent_status_reader`]: an icon is a property of the agent rather than
|
||||
/// a report about it, so there is no cadence it could be late against.
|
||||
///
|
||||
/// Also starts creating the bucket, which the agents writing it cannot do.
|
||||
fn agent_icon_reader(
|
||||
status: Option<&Arc<status::StatusReader>>,
|
||||
) -> Option<Arc<agent_icon::AgentIconReader>> {
|
||||
status.map(|s| Arc::new(agent_icon::AgentIconReader::new(s.queue_client())))
|
||||
let reader = Arc::new(agent_icon::AgentIconReader::new(status?.queue_client()));
|
||||
let creating = Arc::clone(&reader);
|
||||
tokio::spawn(async move { creating.create_when_connected().await });
|
||||
Some(reader)
|
||||
}
|
||||
|
||||
/// A hive name that is shaped like one and names a hive this swarm has.
|
||||
|
|
@ -2034,9 +2039,6 @@ const ICON_MAX_AGE: u32 = 300;
|
|||
/// harness's own `GET /icon` already has, so a caller falls back
|
||||
/// client-side on a failed load rather than probing first.
|
||||
///
|
||||
/// ⚠️ Until the agent-side publisher lands (see
|
||||
/// `swarm_queue_client::agent_icon`), that 404 is every agent's answer.
|
||||
///
|
||||
/// 🩸 **The body is an untrusted document served from this daemon's own
|
||||
/// origin**, and an SVG can carry script. The response headers say it may
|
||||
/// not run any: `Content-Security-Policy: sandbox` with no `allow-scripts`
|
||||
|
|
|
|||
Loading…
Reference in a new issue