From fcb8a594bbf599184cbf8cc7e33fc511587adb29 Mon Sep 17 00:00:00 2001 From: atlas Date: Thu, 17 Sep 2026 19:00:12 +0200 Subject: [PATCH] swarm-controller: make socketPath readOnly instead of asserting it readOnly makes a bad socketPath inexpressible rather than diagnosed after the fact. Since readOnly rejects any definition including one arriving through a rename shim, drop the deploy.nix rename entry for it and the fixture line exercising it, and update the controllerOldPath comment's shim count from seven to six. Refs #4208 --- nix/host-modules/deploy.nix | 4 ---- nix/host-modules/swarm-controller.nix | 21 +-------------------- nix/module-eval.nix | 5 ++--- 3 files changed, 3 insertions(+), 27 deletions(-) diff --git a/nix/host-modules/deploy.nix b/nix/host-modules/deploy.nix index d89a1e7d..4b881ea3 100644 --- a/nix/host-modules/deploy.nix +++ b/nix/host-modules/deploy.nix @@ -69,10 +69,6 @@ in [ "services" "hyperhive" "swarm" "controller" "enable" ] [ "services" "hyperhive" "deploy" "swarm-controller" "enable" ] ) - (lib.mkRenamedOptionModule - [ "services" "hyperhive" "swarm" "controller" "socketPath" ] - [ "services" "hyperhive" "deploy" "swarm-controller" "socketPath" ] - ) (lib.mkRenamedOptionModule [ "services" "hyperhive" "swarm" "controller" "forgeTokenFile" ] [ "services" "hyperhive" "deploy" "swarm-controller" "forgeTokenFile" ] diff --git a/nix/host-modules/swarm-controller.nix b/nix/host-modules/swarm-controller.nix index aaf686a2..d3f12383 100644 --- a/nix/host-modules/swarm-controller.nix +++ b/nix/host-modules/swarm-controller.nix @@ -447,6 +447,7 @@ in socketPath = lib.mkOption { type = lib.types.str; default = "/run/swarm-controller/controller.sock"; + readOnly = true; description = '' Unix socket the daemon serves on, and the path the gateway's nginx proxies to. @@ -720,26 +721,6 @@ in state directory. ''; } - { - assertion = - let - dir = builtins.dirOf deployCfg.swarm-controller.socketPath; - in - dir != "/run/hyperhive" && dir != "/run/hive" && dir != "/run"; - message = '' - services.hyperhive.deploy.swarm-controller.socketPath puts the - controller socket in - ${builtins.dirOf deployCfg.swarm-controller.socketPath}, a - directory that carries other sockets. - - The controller socket is 0666 and the gateway's nginx is given - its directory, so that directory is the access control. - /run/hyperhive holds host.sock — the host ADMIN socket — and - /run/hive holds the per-agent and priv sockets. Give the - controller a directory of its own (the default, - /run/swarm-controller, is one). - ''; - } ]; systemd.services.swarm-controller = { diff --git a/nix/module-eval.nix b/nix/module-eval.nix index 7c819347..9b4fca63 100644 --- a/nix/module-eval.nix +++ b/nix/module-eval.nix @@ -201,13 +201,12 @@ let deploy.matrix.maxRequestSize = 99000000; }; - # `enable` is spelled the OLD way like everything else here, so all seven - # of the controller's shims are exercised rather than six. + # `enable` is spelled the OLD way like everything else here, so all six + # of the controller's shims are exercised rather than five. controllerOldPath = hive { swarm.controller.enable = true; swarm.controller.package = pkgs.emptyDirectory; swarm.controller.swarmctlPackage = pkgs.emptyDirectory; - swarm.controller.socketPath = "/run/test-ctrl/ctrl.sock"; swarm.controller.forgeTokenFile = "/run/secrets/ctrl-forge.token"; swarm.controller.authBridgeUrl = "http://127.0.0.1:19097"; swarm.controller.queue.clientSecretFile = "/run/secrets/ctrl-queue.secret";