hive-priv: publish config files by rename, bound the toplevel build

Every file hive-priv writes for another reader now goes through one
StagedFile: a temp with a unique dot-prefixed `.partial` name in the
destination directory, created O_EXCL|O_NOFOLLOW at its final mode
(and owner, where one is set), fsynced, renamed onto the final name
relative to a directory fd, then the directory fsynced. Dropping it
unpublished unlinks the temp.

- write_resource_limits wrote its systemd drop-in in place, so a
  concurrent daemon-reload could load a truncated file.
- sync_agent_tmpfiles staged through a fixed `.tmp` name, so two
  overlapping syncs shared one inode and one could publish the other's
  bytes, or a mix.
- write_nspawn_flags rewrote /etc/nixos-containers/<c>.conf in place;
  it now keeps the file's existing owner and mode.
- write_agent_dir_file (agent tokens, sidecars, pause marker) already
  renamed, but through a fixed temp opened O_TRUNC, with no fsync.
- write_bridge_dns_marker_in truncated and wrote the marker in place;
  a leaf the container planted (symlink, FIFO) is now replaced by the
  rename instead of refused.
- register_ci_runner must keep writing in place (nspawn pins the
  bind-mounted inode); it now creates the file 0600 when the tmpfiles
  seed is missing, instead of at the umask's mode until the chmod.

nix_build_toplevel now runs nix as its own process-group leader and,
after one hour, SIGKILLs the group and fails with "timed out after
3600s". One hour is four times CI's observed cold-cache flake check.

Refs #4723
This commit is contained in:
atlas 2026-09-26 19:39:50 +02:00 • committed by mara
commit fc85d0ee7e

File diff suppressed because it is too large Load diff