Skip to content

fix(sites): don't list the snippet dir in ReadWritePaths when web.enable is off - #198

Open
defangdevs wants to merge 1 commit into
masterfrom
fix/sites-rwp-web-disabled
Open

fix(sites): don't list the snippet dir in ReadWritePaths when web.enable is off#198
defangdevs wants to merge 1 commit into
masterfrom
fix/sites-rwp-web-disabled

Conversation

@defangdevs

Copy link
Copy Markdown
Owner

Master is red and, more importantly, a default (web-less) agent-box no longer starts any agent sessions.

What broke

7b687b9 (the fix for #195, ~/sites being read-only in the agent's own namespace) added /var/lib/agent-box-sites/<user> to the agent unit's ReadWritePaths unconditionally. The tmpfiles rule that creates that directory lives inside mkIf (cfg.enable && cfg.web.enable), and web.enable is a mkEnableOption — default off. With web off the path never exists, and ProtectSystem=strict namespace setup fails hard:

agent-box-agent.service: Failed to set up mount namespacing:
  /var/lib/agent-box-sites/agent: No such file or directory
agent-box-agent.service: Failed at step NAMESPACE ... status=226/NAMESPACE

The unit never starts — no tmux sessions at all — and restart-loops (the counter passed 427 in the CI run). tests/memory-protection.nix, the only test that runs with web off, timed out on wait_for_unit: https://github.com/defangdevs/agent-box/actions/runs/31016454644

The parent commit's reasoning ("tmpfiles-created at sysinit, long before this unit, so no - prefix") is right about ordering — it just doesn't hold when the rule isn't emitted at all.

The fix

Guard the entry on cfg.web.enable, mirroring what gates the tmpfiles rule.

Deliberately still no - prefix: a directory that is genuinely missing while web is on should fail loudly rather than silently reverting to the EROFS that #195 was about.

Verification

Both node configs evaluated directly, no VM boot needed:

config effective ReadWritePaths
web off (memory-protection) ["/home/agent"]
web on (self-serve-domain) ["/home/agent" "/var/lib/agent-box-sites/agent"]

So the #195 flow keeps working where it applies, and the web-off box boots again.

memory-protection now asserts the entry is absent, so the web-off case has an explicit guard instead of only failing indirectly via wait_for_unit.

Also run natively on aarch64: module-generated-up-to-date (regenerated modules/agent-box.nix from .nix.in), the ty/ruff testScript gate, and a drvPath eval of all seven VM tests.

Note: the deploy-test leg is expected-red on master for unrelated reasons (#186/#190).

Opened from a webhook triage session that picked up the #195 close event.

🤖 Generated with Claude Code

https://claude.ai/code/session_014Kq2nqcWR5Y6aryf8WzWbs

7b687b9 added /var/lib/agent-box-sites/<user> to the agent unit's
ReadWritePaths unconditionally, but the tmpfiles rule that creates that
directory lives inside `mkIf (cfg.enable && cfg.web.enable)`. web.enable
is a mkEnableOption, so on a default box the path never exists and
systemd fails the whole namespace setup:

    agent-box-agent.service: Failed to set up mount namespacing:
      /var/lib/agent-box-sites/agent: No such file or directory
    agent-box-agent.service: Failed at step NAMESPACE ... 226/NAMESPACE

The unit then never starts at all — no tmux sessions on any web-less
deployment — and it restart-loops (counter passed 427 in CI). This broke
tests/memory-protection.nix on master, the one test that runs with web
off, which is how it surfaced.

Guard the entry on cfg.web.enable, matching what gates the tmpfiles
rule. Deliberately still no `-` prefix: a dir that is genuinely missing
while web IS on should stay loud rather than silently reverting to the
EROFS the parent commit fixed.

memory-protection now asserts the entry is absent, so the web-off case
has an explicit guard instead of only failing via wait_for_unit.

Verified by evaluating both node configs:
  web off -> ["/home/agent"]
  web on  -> ["/home/agent" "/var/lib/agent-box-sites/agent"]

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014Kq2nqcWR5Y6aryf8WzWbs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants