Second increment of the per-crate README effort, covering the rest of the infra/wire/priv column: hive-priv, hive-metric, hive-types, hive-sh4re, hive-core-agent-sock, hive-agent-sock. Same shape as the first batch — purpose + when-to-use, and point at the crate-root //! docs plus the relevant docs/ pages rather than duplicating them. Wires readme = "README.md" into each Cargo.toml [package]. Disjoint from the batch-1 crates, so the two increments compose cleanly.
32 lines
1.6 KiB
Markdown
32 lines
1.6 KiB
Markdown
# hive-priv
|
|
|
|
The minimal **root privileged-helper** for hive-c0re. It runs as root and
|
|
exposes a narrow unix socket at `/run/hive/priv.sock` that accepts `PrivRequest`
|
|
JSON lines and performs only the handful of operations that genuinely require
|
|
root — bind-mount edits, `nsenter` into a container, btrfs subvolume ops. All
|
|
coordination logic (broker, HTTP, scheduling) stays in the *unprivileged*
|
|
`hive-c0re` process, which delegates here.
|
|
|
|
## Why it exists
|
|
|
|
Privsep. `hive-c0re` runs as the unprivileged `hive-core` user so a bug or a
|
|
prompt-injection in the large daemon can't directly wield root. The few root
|
|
operations it needs are funnelled through this small, auditable helper instead.
|
|
See `docs/boundary.md` and `docs/security.md` for the privilege boundary.
|
|
|
|
## Security model
|
|
|
|
- **Strict allowlist.** Every request is validated against a container-name
|
|
allowlist before any filesystem or process operation — only names matching the
|
|
hive convention (`h-*`, the manager container, known sibling service
|
|
containers) are accepted.
|
|
- **No pass-through.** Every `PrivRequest` variant maps to a single known
|
|
operation; there is no arbitrary-command escape hatch.
|
|
- **Socket-activated, always.** systemd binds `/run/hive/priv.sock`
|
|
(`SocketGroup=hive-core`, `0660`) and passes the listener as fd 3
|
|
(`LISTEN_FDS`); the helper requires this and has no self-bind fallback, so dev
|
|
and prod take the identical path and the group grant always holds.
|
|
|
|
The wire contract (`PrivRequest` / response types) lives in the separate
|
|
`hive-priv-sock` crate so this root binary depends on just the protocol shapes,
|
|
not the whole daemon-shared crate.
|