No description
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
JMARyA f96aea44e2
All checks were successful
moira/threads moira/threads — definitions compiled
moira/flake/env.path.620119b75bea3514@x86_64-linux env.path.620119b75bea3514 — built
moira/publish moira/publish — succeeded
Make the admin face a socket, and teach the CLI to speak it
The admin face is now the unix socket alone. `--admin-addr` defaults to
`none` and exists only for the case a socket cannot serve: administering
a daemon from another machine, or a remote Prometheus reaching
/metrics. It still demands a token and still refuses a non-loopback bind
without one.

The enabling piece is one HTTP client that speaks both transports
(ore-core/src/wire.rs). ureq has no unix support, and moving only the
admin paths to the socket would have put a seam straight through `ore
snapshot`, which uses both faces in a single command. So Endpoint
::{Http,Unix} carries everything now, including the streaming pull and
push with their progress counters. `ureq::` no longer appears in
sync.rs, and the CLI's own socket client was deleted rather than kept
beside it — there is one implementation.

    ore --daemon unix:/var/lib/ore/.ore/ored.sock state list
    ore --daemon unix:/var/lib/ore/.ore/ored.sock snapshot data --from ./w -m x

0660, not the 0600 I had documented. Owner-only makes the socket
unusable by the case that most needs it — a client running as another
user on the same machine, which is what services.ore.backups.<n>.user
exists for. An operator can add a user to the daemon's group; they
cannot chmod a socket the daemon recreates on every start. The boundary
is the group.

---

I also backed out auto-preferring the socket in discovery. Routing there
when a node directory has one is the right end state — the daemon is
meant to be the single writer of .ore/, and a CLI opening the same node
directly while a daemon holds it is the concurrency the design forbids.
The gate showed why it cannot land yet: `ore verify` reads attestations
straight from the store, has no daemon equivalent, and simply started
failing. That is now a named prerequisite in access-and-daemon.md rather
than a silent gap: every command needs a daemon path first.

Each gate run found something real. `ore snapshot` over unix: failing on
EmptyHost because the sync transport was still ureq-only; `ore verify`
breaking under auto-discovery; smoke and two-node-push still waiting on
the admin TCP port this commit turns off. Fixed before it could bite: a
HEAD reply advertises the Content-Length its body would have had, so
believing the header parks a reader on bytes that never arrive — the
socket client frames HEAD as empty regardless.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01H1WnJ9ZHjid2ZDGm12qqJZ
2026-09-13 02:57:46 +02:00
.moira/envs feat(nix): add moira publish pipeline for the ore container image 2026-07-01 19:27:48 +02:00
.pi Add repository backend foundation and locks 2026-09-06 15:19:51 +02:00
crates Make the admin face a socket, and teach the CLI to speak it 2026-09-13 02:57:46 +02:00
docs Make the admin face a socket, and teach the CLI to speak it 2026-09-13 02:57:46 +02:00
nix Make the admin face a socket, and teach the CLI to speak it 2026-09-13 02:57:46 +02:00
openspec Validate thin backend foundation 2026-09-06 16:29:23 +02:00
todo Make the admin face a socket, and teach the CLI to speak it 2026-09-13 02:57:46 +02:00
.envrc WIP: init 2026-06-30 00:41:59 +02:00
.gitignore Add read-only tokens, and un-red the NixOS gate 2026-09-12 00:40:01 +02:00
Cargo.lock feat(merge): three-way snapshot merge with per-path drivers 2026-07-09 23:01:15 +02:00
Cargo.toml feat(merge): three-way snapshot merge with per-path drivers 2026-07-09 23:01:15 +02:00
flake.lock feat(nix): add moira publish pipeline for the ore container image 2026-07-01 19:27:48 +02:00
flake.nix Consolidate CLI command model 2026-07-12 04:40:59 +02:00
README.md Add read-only tokens, and un-red the NixOS gate 2026-09-12 00:40:01 +02:00
shell.nix Move shell definition under nix 2026-07-12 04:12:16 +02:00

Ore

Ore is a prototype state system: persistent data is stored as versioned,
content-addressed state, and backups, archives, sync, materialization, and future
filesystem views all sit on that one model.

Node  -> State -> Branch -> Snapshot -> Tree -> Entry

The important rule is:

data       = immutable, content-addressed objects
references = mutable, named branch/tag pointers

A .ore/ directory is a node: a sovereign machine identity plus one opaque
object store. A node can hold many states. A state owns no directory; you
snapshot a directory into a state and materialize or checkout a state back
out to a directory.

Where to start

Crates

  • ore-core — Node façade over store, state, refs, fs, sync, and crypto.
  • ore-cli — the ore command.
  • ore-daemon — ored, the HTTP API / sync / metrics process.
  • ore-store — opaque content-addressed store, loose objects, packs, indexes.
  • ore-state — snapshots, refs, history walking, diff/merge glue, fsck.
  • ore-object — canonical object model and serialization.
  • ore-fs — directory ingest and materialization.
  • ore-chunk — content-defined chunking.
  • ore-crypto — per-state encryption and key wrapping.
  • ore-diff, ore-merge — pluggable content diff/merge drivers.
  • ore-id, ore-encoding — content IDs and wire primitives.

Quick sketch

cargo build

ore init
mkdir data
echo hello > data/note.txt
ore snapshot default --from data -m first
ore log default
ore restore default main restored