atlas
0e3df82504
feat(#972): tighten hive-priv systemd sandbox — ProtectSystem=strict + ReadWritePaths
Replace ProtectSystem=false with ProtectSystem=strict now that privsep
is complete (issue #702 closed) and hive-c0re runs as the non-root
hive-core user.
ReadWritePaths carves out the six paths hive-priv must write to at
runtime; everything else is read-only:
/etc/nixos-containers — writes <container>.conf (bind-mounts,
network isolation, nspawn flags)
/run/hive — fallback socket bind when LISTEN_FDS absent
/run/hive-agent — chown/chmod per-agent socket directories
/run/systemd — container@ drop-ins (resource limits) and
machinectl/systemd-machined machine state
/var/lib/nixos-containers — container rootfs (nixos-container script)
/nix — nix store + profile updates during
container create/update
PrivateTmp=true (already set) keeps /tmp private.
StateDirectory=hive-priv (already set) keeps /var/lib/hive-priv writable
for nix's fetch/eval cache (HOME points there).
nix flake check --no-build passes.
|
2026-06-03 16:57:01 +02:00 |
| .. |
|
docs
|
chore: scrub #NNN issue references from code comments and nix descriptions
|
2026-06-01 13:30:52 +02:00 |
|
forge-theme
|
forge: use branding/hyperhive.svg for logo and favicon
|
2026-05-21 17:50:46 +02:00 |
|
modules
|
feat(#972): tighten hive-priv systemd sandbox — ProtectSystem=strict + ReadWritePaths
|
2026-06-03 16:57:01 +02:00 |
|
packages
|
chore: scrub #NNN issue references from code comments and nix descriptions
|
2026-06-01 13:30:52 +02:00 |
|
templates
|
fix(#702): heal proposed-config ownership in agent-user-migrate
|
2026-06-03 00:37:55 +02:00 |
|
assets.nix
|
docs/gotchas.md: extract nix/{assets,docs,templates/weston-vnc} prose (#718 batch 3)
|
2026-05-31 15:24:39 +02:00 |
|
frontend.nix
|
frontend: npm dependency updates (#681)
|
2026-05-31 01:29:35 +02:00 |