Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/swarm-controller/src
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 78d8d69c7f swarm-controller: mint each hive's matrix sender token
A hive whose homeserver runs on another host has no local
matrix-appservice-token, so hive-c0re's matrix sweep returned before
reaching the store read in ensure_hive_user: no @hive-<name>: token, no
Space, no chat room, no invites, and a sweep-health banner.

swarm-controller now mints @hive-<name>: with the swarm appservice
token for every hive in its directory, as a MintHiveSenderToken job
node queued by a five-minute pass, and stores it at
swarm/hives/<name>/matrix/sender-token, the same matrix::Credential
swarm-matrix-ctl writes there. It is keep-if-live, reusing agent_token's
classify/plan: a stored token whoami confirms as @hive-<name>: is left
alone, so only an absent or dead one is minted. agent_token's probe and
mint steps are lifted into probe_at/mint_at so both passes share them.

swarm-matrix-ctl mint still writes the path for its own hive when it is
empty. If both mint an empty path at once, one token is invalidated
(same pinned device); the next pass classifies it Revoked and re-mints.

hive-c0re's ensure_all no longer returns when there is no local
as_token. ensure_hive_user reads the store first on every sweep and
overwrites its token file when the store's token differs, keeps the
file when the store has none, mints with the local as_token only when
neither holds one, and fails with one error when there is nothing at
all. The decision is sender_source, unit-tested.

The controller's bao policy gains create/read/update on
swarm/hives/+/matrix/sender-token (`+`, since `*` is a glob only at the
end of a path), pinned in module-eval.

Refs #4427
2026-09-29 22:14:40 +02:00
..
forge swarm-controller: fix broken rustdoc intra-doc link to AGENT_TOKEN_NAME 2026-09-29 22:13:32 +02:00
matrix_account swarm-controller: mint each hive's matrix sender token 2026-09-29 22:14:40 +02:00
agent_icon.rs swarm: let an agent publish its own icon 2026-09-28 13:47:37 +02:00
agent_identity.rs swarm: tests and docs for the queue-credential revocation 2026-09-28 23:46:17 +02:00
agent_renewal.rs swarm-controller: backfill a missing queue-secret mint time instead of re-minting it 2026-09-28 22:24:07 +02:00
agent_state_stream.rs swarm-controller: relay an agent's hive-free subjects beside the old ones 2026-09-28 08:24:52 +02:00
agent_status.rs swarm-ui: add agent start/stop, backed by the wanted-state route 2026-09-02 19:57:04 +02:00
auth.rs swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
config_pr.rs swarm-controller: fix stale route reference in snapshot's doc comment 2026-08-19 22:27:12 +02:00
forge.rs swarm-controller: sweep agents' legacy hyperhive-* forge tokens at start 2026-09-29 22:13:32 +02:00
issue_report.rs swarm-controller: answer 404, not 503, for an issue-report on a nonexistent repo 2026-09-24 16:38:47 +02:00
main.rs swarm-controller: mint each hive's matrix sender token 2026-09-29 22:14:40 +02:00
matrix_account.rs swarm-controller: mint each hive's matrix sender token 2026-09-29 22:14:40 +02:00
otel_http_client.rs swarm-queue-client: request the bearer-authz scope when minting an agent token 2026-09-17 09:51:44 +02:00
queue_identity.rs swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
read_policy.rs swarm: say the read policy names the hive it is written for 2026-09-12 11:41:01 +02:00
status.rs swarm-controller: make status::render/row pub(crate) so agent_status.rs's doc links resolve 2026-09-02 10:20:29 +02:00
store.rs fix doc-comment pointers broken by the module-eval split 2026-09-20 04:31:08 +02:00
term_stream.rs swarm-controller: relay an agent's hive-free subjects beside the old ones 2026-09-28 08:24:52 +02:00
vcs_metrics.rs swarm-controller: read the queue client secret from the store, drop the file 2026-09-28 19:01:05 +02:00
wanted.rs swarm-controller: trim oversized comments, drop a trivial wrapper fn 2026-09-18 22:59:29 +02:00
webhook.rs swarm-controller: own the swarm-wide forge objects; hive-c0re stops creating them 2026-09-25 08:36:05 +02:00