The daemon reads each account's token from `swarm/agents/<agent>/matrix/` as the agent itself, inside its own container, and falls back to the file only when the store has none. This is #4519's read, without its `main` carve-out: the swarm now mints `main` there and no hive writes the file. The daemon unit gets the agent's store identity, spelled the way forge-token.nix spells it. A timer re-starts it while it is down: a token the swarm mints or replaces in the store changes no file, so the path watcher never fires for it, and a daemon that exited on a replaced token would otherwise stay down until the container restarts.
59 lines
2.6 KiB
Rust
59 lines
2.6 KiB
Rust
//! Per-agent filesystem paths used by `hive-matrix-daemon`.
|
|
//!
|
|
//! All paths are overridable via env vars for dev / test scenarios and
|
|
//! to let the harness point the daemon at non-default locations when
|
|
//! the operator overrides `services.hyperhive.agent.matrix.*` options.
|
|
|
|
use std::path::PathBuf;
|
|
|
|
/// Resolve the matrix access-token file path. Override via
|
|
/// `HIVE_MATRIX_TOKEN_FILE`; default is `<HYPERHIVE_STATE_DIR>/matrix-token`,
|
|
/// where a hive used to write the `main` account's token (the daemon now reads
|
|
/// it from the store first; see `main.rs`'s `account_token`).
|
|
#[must_use]
|
|
pub fn token_file() -> PathBuf {
|
|
if let Some(p) = std::env::var_os("HIVE_MATRIX_TOKEN_FILE") {
|
|
return PathBuf::from(p);
|
|
}
|
|
let state_dir = std::env::var("HYPERHIVE_STATE_DIR").unwrap_or_default();
|
|
PathBuf::from(format!("{state_dir}/matrix-token"))
|
|
}
|
|
|
|
/// Resolve the homeserver URL from `HIVE_MATRIX_URL`, or `None` when the
|
|
/// harness didn't set one.
|
|
///
|
|
/// There is deliberately no built-in default. A hardcoded `localhost:8008`
|
|
/// used to stand in here, on the reasoning that the tuwunel container shares
|
|
/// the host netns — but *this daemon runs inside an agent*, which does not, so
|
|
/// that address named the agent itself. Unset means the hive has no homeserver
|
|
/// to offer this agent, and the daemon no-ops exactly as it does without a
|
|
/// token; guessing would be a value that starts fine and then talks to the
|
|
/// wrong machine.
|
|
#[must_use]
|
|
pub fn homeserver_url() -> Option<String> {
|
|
std::env::var("HIVE_MATRIX_URL").ok()
|
|
}
|
|
|
|
/// Persistent sqlite store directory for matrix-sdk's state (event
|
|
/// cache, devices, etc.). Lives under the per-agent state dir so it
|
|
/// survives container restart but gets wiped on `destroy --purge`.
|
|
#[must_use]
|
|
pub fn matrix_state_dir() -> PathBuf {
|
|
let state_dir = std::env::var("HYPERHIVE_STATE_DIR").unwrap_or_default();
|
|
PathBuf::from(format!("{state_dir}/matrix-sdk-state"))
|
|
}
|
|
|
|
/// Resolve the live-accounts snapshot file the daemon writes after
|
|
/// startup restores. Override via `HIVE_MATRIX_ACCOUNTS_FILE`; default
|
|
/// is `<HYPERHIVE_STATE_DIR>/matrix-accounts.json` — the host-visible
|
|
/// per-agent state dir (sibling to `matrix-token`) that hive-c0re's
|
|
/// dashboard reads to backfill live up/down status + the effective
|
|
/// homeserver for each provisioned account.
|
|
#[must_use]
|
|
pub fn accounts_file() -> PathBuf {
|
|
if let Some(p) = std::env::var_os("HIVE_MATRIX_ACCOUNTS_FILE") {
|
|
return PathBuf::from(p);
|
|
}
|
|
let state_dir = std::env::var("HYPERHIVE_STATE_DIR").unwrap_or_default();
|
|
PathBuf::from(format!("{state_dir}/matrix-accounts.json"))
|
|
}
|