`Coordinator::set_paused` wrote the marker directly with `std::fs::write`
from hive-c0re, which runs as the unprivileged `hive-core` user. The
agent's harness dir is chowned to the agent user on every container boot
(`user.nix`'s activation chown), mode 0755 — so hive-core can stat the
marker but gets EACCES creating or unlinking it. Pause therefore only
ever worked on an agent that had never booted; the read side works
because a stat needs traverse, not write, which is why the paused pill
and `is_paused` looked healthy.
Route both directions through hive-priv, the root helper that already
owns the other writes into agent-owned directories:
- `PrivRequest::SetAgentPaused { agent_name, paused }`, with the marker
filename constant moved to hive-priv-sock. That is the narrowest crate
all three sides share (hive-priv deliberately does not depend on
hive-sh4re, which re-exports it for the in-container resolver). A
private copy on any one side would break pause silently, since every
reader just sees "no marker".
- `write_agent_state_file` generalised to `write_agent_dir_file`, taking
the target directory: `state/` and `harness/` are both agent-owned,
which is the same reason both need root.
- resume unlinks via `remove_file`, which acts on the leaf and never
follows a symlink — an agent could otherwise plant a link at the
marker path and have root delete an arbitrary file.
`Coordinator::set_paused` becomes an async round-trip; its three call
sites were already async. Both directions stay idempotent because the
dashboard toggle and `hivectl pause|resume` fire without reading the
current state first.
57 lines
2.7 KiB
Rust
57 lines
2.7 KiB
Rust
//! Shared in-container filesystem-path resolution.
|
|
//!
|
|
//! Every process that runs inside an agent container - the harness plus
|
|
//! the out-of-process MCP daemons (bash, matrix, ...) - must resolve the
|
|
//! harness directory layout identically. These helpers live here so the
|
|
//! resolution exists in exactly one place rather than being mirrored
|
|
//! across crates.
|
|
|
|
use std::path::PathBuf;
|
|
|
|
/// Base harness directory for the current agent. Uses `HYPERHIVE_HARNESS_DIR`
|
|
/// if set (injected by the hive-c0re meta flake after the harness/state
|
|
/// split). For pre-split / dev deployments where it isn't set, falls back to
|
|
/// a `harness/` sibling of `HYPERHIVE_STATE_DIR`, and finally to
|
|
/// `/agents/{HIVE_LABEL}/harness` when neither dir env var is present — the
|
|
/// shape the harness derives from its label alone.
|
|
#[must_use]
|
|
pub fn harness_dir() -> PathBuf {
|
|
if let Some(p) = std::env::var_os("HYPERHIVE_HARNESS_DIR") {
|
|
return PathBuf::from(p);
|
|
}
|
|
if let Some(state) = std::env::var_os("HYPERHIVE_STATE_DIR") {
|
|
let state_path = PathBuf::from(&state);
|
|
if let Some(parent) = state_path.parent() {
|
|
return parent.join("harness");
|
|
}
|
|
}
|
|
let label = std::env::var("HIVE_LABEL").unwrap_or_default();
|
|
PathBuf::from(format!("/agents/{label}/harness"))
|
|
}
|
|
|
|
/// File name of the pause marker inside the harness dir. Re-exported from
|
|
/// `hive-priv-sock`, which owns the definition because hive-priv (root) is
|
|
/// the component that actually creates and unlinks the marker — hive-c0re
|
|
/// runs unprivileged and cannot write to the agent-owned harness dir — and
|
|
/// hive-priv deliberately does not depend on this crate. Shared so the
|
|
/// in-container resolver below, hive-c0re's host-side one (which builds the
|
|
/// same path from `/var/lib/hyperhive/agents/{name}/harness`) and the
|
|
/// privileged writer cannot drift apart.
|
|
pub use hive_priv_sock::PAUSED_MARKER_FILE;
|
|
|
|
/// Marker file whose presence means "this agent is paused": the harness
|
|
/// keeps serving its web UI and MCP daemons but drives no turns, so
|
|
/// inbox messages queue up unacked until it's removed.
|
|
///
|
|
/// It lives in the harness dir rather than `state/` because `state/` is
|
|
/// the agent's own scratch space — this is harness control state. The
|
|
/// harness dir is bind-mounted from the host, so the marker is the
|
|
/// single source of truth for both sides: the harness stats it to gate
|
|
/// the turn loop, and hive-c0re stats it to render the paused
|
|
/// indicator and creates/removes it for `hivectl pause|resume`. Being a
|
|
/// plain file, it survives container restarts — pause is sticky by
|
|
/// construction, and works even when the harness isn't running.
|
|
#[must_use]
|
|
pub fn paused_marker() -> PathBuf {
|
|
harness_dir().join(PAUSED_MARKER_FILE)
|
|
}
|