From cb57e6560fe7767e79b87473a11261fbb82ce84c Mon Sep 17 00:00:00 2001 From: Lorenz Leutgeb Date: Mon, 27 Apr 2026 18:10:52 +0200 Subject: [PATCH] node: Rename systemd Credentials Because we changed our main domain from radicle.xyz to radicle.dev, we should also change our systemd credential identifiers. Handling is move into a new function, which also checks the old names for backwards compatibility. --- CHANGELOG.md | 1 + crates/radicle-node/src/main.rs | 78 +++++++++++++++++++++------------ 2 files changed, 52 insertions(+), 27 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9860d73f..841415c3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -13,6 +13,7 @@ Following a domain move of the project, the names of the bootstrap nodes change: `{iris,rosa}.radicle.{xyz → network}`. Old names in the Radicle configuration will be detected and cause warnings to be printed. +The systemd credential IDs that node uses change: `{xyz → dev}.radicle.node.*`. ## New Features diff --git a/crates/radicle-node/src/main.rs b/crates/radicle-node/src/main.rs index 60d4fca8..7e3bb7c2 100644 --- a/crates/radicle-node/src/main.rs +++ b/crates/radicle-node/src/main.rs @@ -213,6 +213,55 @@ enum ExecutionError { }, } +/// Loads a credential from systemd, if available. +/// +/// The credential ID should only be given as a suffix, as this function will +/// try different prefixes for backwards compatibility reasons. +/// +/// The prefix `dev.radicle.node` is the preferred prefix, and should be used +/// for new credentials, while the prefix `xyz.radicle.node` is deprecated and +/// should be migrated away from. If it is used, a warning is logged. +#[cfg(all(feature = "systemd", target_os = "linux"))] +fn load_credential(id_suffix: &str) -> Option { + const INFIX_NODE: &str = ".radicle.node."; + const PREFIX_DEV: &str = "dev"; + const PREFIX_XYZ: &str = "xyz"; + + let id_dev = format!("{}{}{}", PREFIX_DEV, INFIX_NODE, id_suffix); + + let credential = match radicle_systemd::credential::path(&id_dev) { + Ok(option) => option, + Err(err) => { + log::warn!(target: "node", "Failed to obtain path of the passphrase file via systemd credential with '{id_dev}': {err}"); + None + } + }; + + let credential = credential.or_else(|| { + let id_xyz = format!("{}{}{}", PREFIX_XYZ, INFIX_NODE, id_suffix); + match radicle_systemd::credential::path(&id_xyz) { + Ok(option) => { + log::warn!(target: "node", "Obtain path of the passphrase file via systemd credential with '{id_xyz}'. Using this credential ID is discouraged. Please change the ID to '{id_dev}'."); + option + }, + Err(err) => { + log::warn!(target: "node", "Failed to obtain path of the passphrase file via systemd credential with '{id_xyz}': {err}"); + None + } + } + }); + + credential.and_then(|ref path| { + match std::fs::read_to_string(path) { + Ok(passphrase) => Some(passphrase), + Err(err) => { + log::warn!(target: "node", "Failed to read passphrase from '{}': {err}", path.display()); + None + } + } + }) +} + fn execute(options: Options) -> Result<(), ExecutionError> { let home = profile::home()?; @@ -244,39 +293,14 @@ fn execute(options: Options) -> Result<(), ExecutionError> { let passphrase = None; #[cfg(all(feature = "systemd", target_os = "linux"))] - let passphrase = passphrase.or_else(|| { - const ID: &str = "xyz.radicle.node.passphrase"; - match radicle_systemd::credential::path(ID) { - Err(err) => { - log::warn!(target: "node", "Failed to obtain path of the passphrase file via systemd credential with '{ID}': {err}"); - None - }, - Ok(Some(ref path)) => match std::fs::read_to_string(path) { - Ok(passphrase) => Some(passphrase.into()), - Err(err) => { - log::warn!(target: "node", "Failed to read passphrase from '{}': {err}", path.display()); - None - } - } - Ok(None) => None, - } - }); + let passphrase = passphrase.or_else(|| load_credential("passphrase").map(|s| s.into())); let passphrase = passphrase.or_else(profile::env::passphrase); let secret_path = options.secret; #[cfg(all(feature = "systemd", target_os = "linux"))] - let secret_path = secret_path.or_else(|| { - const ID: &str = "xyz.radicle.node.secret"; - match radicle_systemd::credential::path(ID) { - Err(err) => { - log::warn!(target: "node", "Failed to obtain path of the secret key via systemd credential with ID '{ID}': {err}"); - None - }, - Ok(path) => path - } - }); + let secret_path = secret_path.or_else(|| load_credential("secret").map(PathBuf::from)); let secret_path = secret_path .or_else(|| config.node.secret.clone())