From f8a8acae9305b5f7532a2f9d98c4838c5fe81632 Mon Sep 17 00:00:00 2001 From: atlas Date: Fri, 2 Oct 2026 17:54:45 +0200 Subject: [PATCH] github swarm bao: address argus review on #4892 - docs/web-ui/README.md: drop the removed Credentials tile from the H0M3 hub list. - api-error.ts, hive-warn.js: rewrite comments pointing at dashboard/src/credentials.js and credentials.html, now deleted, to state what the code does instead. - swarm-secret-client/src/github.rs: correct the Credential.value doc to the actual read command (bao kv get -format=json | jq .data.data.value), keeping the load-bearing-field-name point. - github-token.nix, agent-github-bao.nix, LinkGithubAccountForm.tsx: restate added comments as current behaviour instead of changelog wording ("has always had", "holds the token now"). Refs #4347 --- docs/web-ui/README.md | 2 +- frontend/packages/shared/src/api-error.ts | 9 ++++----- frontend/packages/shared/src/hive-warn/hive-warn.js | 9 ++++----- .../swarm-ui/src/pages/LinkGithubAccountForm.tsx | 2 +- nix/agent-modules/github-token.nix | 2 +- nix/module-eval/agent-github-bao.nix | 4 ++-- swarm-secret-client/src/github.rs | 5 +++-- 7 files changed, 16 insertions(+), 17 deletions(-) diff --git a/docs/web-ui/README.md b/docs/web-ui/README.md index 0f16df1b..e4adb0d0 100644 --- a/docs/web-ui/README.md +++ b/docs/web-ui/README.md @@ -12,7 +12,7 @@ what you actually do here. Everything starts at the **H0M3 hub**, served at `/` — a grid of tiles linking to every surface (Dashboard, Flow, Logs, Builds, Stats, -Settings, Core, Credentials). Every page links back to H0M3, so you're +Settings, Core). Every page links back to H0M3, so you're never more than one step from the hub. The **dashboard** itself (`/dashboard.html`) is where you'll spend most diff --git a/frontend/packages/shared/src/api-error.ts b/frontend/packages/shared/src/api-error.ts index 3730fbb4..e0c2aedb 100644 --- a/frontend/packages/shared/src/api-error.ts +++ b/frontend/packages/shared/src/api-error.ts @@ -1,11 +1,10 @@ // api-error.ts — reads a failed fetch `Response` into a `ProblemDetails` // (RFC 9457, `application/problem+json`) object, shape-agnostically. // -// Promoted from `dashboard/src/credentials.js`'s original `readErrorBody`, -// which returned a flat message string. This returns the structured object -// instead so a caller — chiefly `ApiErrorPanel` (./api-error-panel/) — can -// render title/status/detail separately and build a useful copy-button -// payload, rather than re-parsing a pre-squashed string. +// Returns the structured object (rather than a flat message string) so a +// caller — chiefly `ApiErrorPanel` (./api-error-panel/) — can render +// title/status/detail separately and build a useful copy-button payload, +// rather than re-parsing a pre-squashed string. // // RFC 9457 is this hive's committed error-body contract for first-party // APIs (mara: "any api of our own responding with error that is not rfc diff --git a/frontend/packages/shared/src/hive-warn/hive-warn.js b/frontend/packages/shared/src/hive-warn/hive-warn.js index 112fb1c6..cb8f5dca 100644 --- a/frontend/packages/shared/src/hive-warn/hive-warn.js +++ b/frontend/packages/shared/src/hive-warn/hive-warn.js @@ -1,10 +1,9 @@ // hive-warn.js — , the shared inline warning-banner -// component. Consolidates three independently-written instances of the -// same thing: `.cred-warning` (credentials.html, static -// markup), `.tombstone-warn` (core.js, JS-built), `.port-conflict` -// (swarm.js, JS-built) — the first two differed only by an +// component. Consolidates what were independently-written instances of +// the same thing, among them `.tombstone-warn` (core.js, JS-built) and +// `.port-conflict` (swarm.js, JS-built) — some differed only by an // undeliberate 10% vs 8% tint, the strongest evidence this was drift, -// not three genuinely different needs. +// not genuinely different needs. // // Purely presentational — no internal state, no lifecycle beyond // attaching its shadow root once. `level` ('info' | 'warning' | 'error', diff --git a/frontend/packages/swarm-ui/src/pages/LinkGithubAccountForm.tsx b/frontend/packages/swarm-ui/src/pages/LinkGithubAccountForm.tsx index 8bd2a3f1..8b4dd6ba 100644 --- a/frontend/packages/swarm-ui/src/pages/LinkGithubAccountForm.tsx +++ b/frontend/packages/swarm-ui/src/pages/LinkGithubAccountForm.tsx @@ -49,7 +49,7 @@ export function LinkGithubAccountForm({ return; } setResult({ status: "done" }); - // The store holds the token now; nothing here needs it. + // The store holds the token; nothing here needs it. setToken(""); } catch (err) { setResult({ status: "error", problem: { detail: String(err) } }); diff --git a/nix/agent-modules/github-token.nix b/nix/agent-modules/github-token.nix index da80d444..1bf9b0d3 100644 --- a/nix/agent-modules/github-token.nix +++ b/nix/agent-modules/github-token.nix @@ -74,7 +74,7 @@ in Group = agentName; RuntimeDirectory = runtimeDir; RuntimeDirectoryMode = "0700"; - # `0600`, the mode `github-token` has always had. + # `0600`, the mode `github-token` has. UMask = "0077"; LoadCredential = [ certCredential diff --git a/nix/module-eval/agent-github-bao.nix b/nix/module-eval/agent-github-bao.nix index acaadd4b..eb8a50b2 100644 --- a/nix/module-eval/agent-github-bao.nix +++ b/nix/module-eval/agent-github-bao.nix @@ -72,8 +72,8 @@ let && lib.hasInfix ".data.data.value | strings" s; } { - # The agent user owns its state dir (./user.nix), and the file keeps the - # `0600` it has always had. + # The agent user owns its state dir (./user.nix), and the file keeps + # its `0600` mode. name = "the fetch runs as the agent, with its own store identity"; ok = let diff --git a/swarm-secret-client/src/github.rs b/swarm-secret-client/src/github.rs index f624600a..0bd92016 100644 --- a/swarm-secret-client/src/github.rs +++ b/swarm-secret-client/src/github.rs @@ -35,8 +35,9 @@ pub fn account_path(agent: &str) -> Result { #[derive(Clone, PartialEq, Eq, Serialize, Deserialize)] pub struct Credential { /// The token. `github-token.nix` reads the store with - /// `bao kv get -field=value`, so this name is load-bearing for a reader - /// this crate does not control. + /// `bao kv get -format=json` and pulls `.data.data.value` out with + /// `jq`, so this name is load-bearing for a reader this crate does not + /// control. pub value: String, }