hyperhive/hive-priv/README.md
atlas bbfc578c95 docs(#2627): add READMEs for the remaining infra crates
Second increment of the per-crate README effort, covering the rest of the
infra/wire/priv column: hive-priv, hive-metric, hive-types, hive-sh4re,
hive-core-agent-sock, hive-agent-sock. Same shape as the first batch —
purpose + when-to-use, and point at the crate-root //! docs plus the
relevant docs/ pages rather than duplicating them. Wires
readme = "README.md" into each Cargo.toml [package].

Disjoint from the batch-1 crates, so the two increments compose cleanly.
2026-07-23 13:16:29 +02:00

32 lines
1.6 KiB
Markdown

# hive-priv
The minimal **root privileged-helper** for hive-c0re. It runs as root and
exposes a narrow unix socket at `/run/hive/priv.sock` that accepts `PrivRequest`
JSON lines and performs only the handful of operations that genuinely require
root — bind-mount edits, `nsenter` into a container, btrfs subvolume ops. All
coordination logic (broker, HTTP, scheduling) stays in the *unprivileged*
`hive-c0re` process, which delegates here.
## Why it exists
Privsep. `hive-c0re` runs as the unprivileged `hive-core` user so a bug or a
prompt-injection in the large daemon can't directly wield root. The few root
operations it needs are funnelled through this small, auditable helper instead.
See `docs/boundary.md` and `docs/security.md` for the privilege boundary.
## Security model
- **Strict allowlist.** Every request is validated against a container-name
allowlist before any filesystem or process operation — only names matching the
hive convention (`h-*`, the manager container, known sibling service
containers) are accepted.
- **No pass-through.** Every `PrivRequest` variant maps to a single known
operation; there is no arbitrary-command escape hatch.
- **Socket-activated, always.** systemd binds `/run/hive/priv.sock`
(`SocketGroup=hive-core`, `0660`) and passes the listener as fd 3
(`LISTEN_FDS`); the helper requires this and has no self-bind fallback, so dev
and prod take the identical path and the group grant always holds.
The wire contract (`PrivRequest` / response types) lives in the separate
`hive-priv-sock` crate so this root binary depends on just the protocol shapes,
not the whole daemon-shared crate.