hyperhive/hive-c0re/src
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 2c066cc871 hive-c0re: pin the two security boundaries that had no test
`is_forbidden` and the webhook-secret load/regenerate path were the last two
entries on the shortlist in hyperhive/hyperhive#3950; the other three landed in
hyperhive/hyperhive#4650. Both are classification logic whose failure mode is
silence, which is why they are worth a test rather than a coverage line.

`is_forbidden` gates the arms that tell an operator a Forgejo admin PATCH was
refused for want of a scope, and which credential to delete and re-mint to fix
it. One of those PATCHes is `ensure_repo_creation_disabled` — the lockdown that
stops an agent creating a repo it owns and self-merging in it. Two tests: a 403
is recognised in both shapes the typed client produces (the spec-listed
`Forbidden` kind and the bare `UnexpectedStatusCode`), and nothing else is —
not a 401, whose remedy is the automatic re-mint one function down, and not a
transport error that never reached the forge at all.

`load_or_generate` grows the path-taking half `load_or_generate_at`, the same
seam `swarm-controller`'s `webhook::load_or_generate_at` already has and for
the same stated reason. Three tests over it: a valid stored secret is returned
verbatim and never rotated (the newline this module writes itself makes the
trim load-bearing, not defensive); a malformed one is replaced by a secret that
reaches *disk*, not just the caller, and is then stable; and each near miss —
empty, whitespace, 63 chars, 65 chars, right length with a non-hex char — is
refused. That last one is the security case: `Hmac::new_from_slice` accepts a
key of any length, empty included, so a relaxed check fails nowhere and just
keys every signature off a guessable value.

Every test was confirmed able to fail: six mutations of the code under test,
each watched red, then reverted. The two halves of the validity check and the
two arms of `is_forbidden` were broken separately, so neither test passes on
one arm alone.
2026-09-23 17:00:44 +02:00
..
agent_config docs+comments: say what changed instead of tagging the tracker item 2026-09-21 22:43:16 +02:00
dashboard topology: drop the parent field and the hierarchy it fed 2026-09-21 22:08:47 +02:00
forge hive-c0re: pin the two security boundaries that had no test 2026-09-23 17:00:44 +02:00
job_queue docs+comments: say what changed instead of tagging the tracker item 2026-09-21 22:43:16 +02:00
lifecycle docs+comments: say what changed instead of tagging the tracker item 2026-09-21 22:43:16 +02:00
socket_server topology: drop the parent field and the hierarchy it fed 2026-09-21 22:08:47 +02:00
stats topology: drop the parent field and the hierarchy it fed 2026-09-21 22:08:47 +02:00
stores topology: drop the parent field and the hierarchy it fed 2026-09-21 22:08:47 +02:00
workers docs+comments: say what changed instead of tagging the tracker item 2026-09-21 22:43:16 +02:00
actions.rs refactor(hive-c0re): drop the request_init_config tool and InitConfig approval 2026-09-14 19:03:44 +02:00
container_view.rs topology: drop the parent field and the hierarchy it fed 2026-09-21 22:08:47 +02:00
coordinator.rs topology: drop the parent field and the hierarchy it fed 2026-09-21 22:08:47 +02:00
dashboard_events.rs remove the 1NFR4 dashboard panel and the now-writer-less audit log 2026-08-31 00:18:21 +02:00
gateway_nginx.rs gateway: $connection_upgrade does not come from recommendedProxySettings 2026-09-02 09:04:24 +02:00
loose_ends.rs hive-agent-mcp, hive-c0re, hive-sh4re: drop agent param from get_loose_ends 2026-09-20 05:36:49 +02:00
main.rs log: send records natively to journald, keep stdout off-unit 2026-09-21 15:52:57 +02:00
matrix.rs matrix: one sender account and one sender token per hive 2026-09-20 22:07:16 +02:00
meta.rs topology: drop the parent field and the hierarchy it fed 2026-09-21 22:08:47 +02:00
migrate.rs docs: repoint eighteen pointers whose section no longer exists 2026-09-02 09:00:23 +02:00
paths.rs matrix: name the credential after the account it authenticates as 2026-09-20 22:07:16 +02:00
priv_client.rs hive-c0re: render the new agent option paths into generated agent flakes 2026-09-17 20:19:30 +02:00
server.rs topology: drop the parent field and the hierarchy it fed 2026-09-21 22:08:47 +02:00
snapshot_push.rs refactor(#2862): one snapshot store per swarm, not one per peer 2026-07-31 22:15:37 +02:00
swarm_agent_status.rs swarm: present tense + no-queue-coordinates wording 2026-09-13 12:01:58 +02:00
swarm_notices.rs swarm: present tense + no-queue-coordinates wording 2026-09-13 12:01:58 +02:00
swarm_queue.rs swarm-queue-based lifecycle notices, replacing push_todo(MANAGER_AGENT) 2026-08-24 14:34:37 +02:00
swarm_status.rs hive-c0re: converge when the controller republishes, not only at boot 2026-09-03 00:36:57 +02:00
test_env.rs test(hive-c0re): one crate-wide lock for env-mutating tests 2026-08-19 01:38:54 +02:00
webhook_secret.rs hive-c0re: pin the two security boundaries that had no test 2026-09-23 17:00:44 +02:00