hop3-rootd
Privileged-operations agent for Hop3. Runs as root; exposes a narrow control-plane API to hop3-server (running unprivileged as the hop3 user) over a Unix domain socket.
See notes/adrs/041-privileged-operations-agent.md for the design rationale and notes/adrs/040-network-firewall-and-port-exposure.md for the firewall integration that motivated v1's op set.
What this is
hop3-rootd is the kernel-boundary executor for Hop3's runtime privileged actions. The unprivileged hop3-server reaches it via a Unix socket; rootd validates each request structurally, applies the privileged action (nftables mutation, nginx reload, etc.), and returns a typed result.
In v1 the operations are:
firewall.add_rule,firewall.remove_rule,firewall.list_rules— manage rules in a dedicatedinet hop3nftables table.nginx.reload,nginx.validate_config— wrap the privileged nginx commands previously granted tohop3-servervia/etc/sudoers.d/hop3(now retired).daemon.health,daemon.handshake— introspection.
What this is not
- A policy enforcement layer. SO_PEERCRED admits the
hop3user; structural validation rejects malformed requests. There is no per-op authorization, no policy file. Operator-level "did you mean this?" prompts live inhop3 deploy, not in rootd. - A general-purpose privileged-shell daemon. Rootd never accepts shell strings; every operation is a typed intent with a fixed argument schema.
Deployment
hop3-rootd ships as a stdlib-only Python package and is installed by hop3-installer alongside hop3-server. It runs as a hardened systemd unit (full ProtectX suite, CapabilityBoundingSet=CAP_NET_ADMIN, syscall filter, resource limits). The socket is at /run/hop3-rootd/socket, mode 0660, group hop3.
Development
# Run unit tests (no privileges needed)
pytest tests/a_unit/ -v
# Run integration tests (requires root + nftables)
sudo pytest tests/b_integration/ -v
# Lint
ruff check src tests
ruff format src tests
License
Apache-2.0 — Copyright (c) 2026, Abilian SAS
Metadata
Release files for hop3-rootd 0.7.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| hop3_rootd-0.7.2.tar.gz | 63.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| hop3_rootd-0.7.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 144.1 kB
Release files / hop3_rootd-0.7.2.tar.gz
| Download URL | hop3_rootd-0.7.2.tar.gz |
|---|---|
| Size | 63.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
fa8d74df56229dfb25b2b814f393fdc661560052fbc7c88b07b3b72f6491d25e
|
|
BLAKE2b-256 checksum How to use checksums |
43d34475d1f0ebfaa263aad2088a6c7d23916ab81b15899b54f4dd866baf0bfe
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.13
|
Release files / hop3_rootd-0.7.2-py3-none-any.whl
| Download URL | hop3_rootd-0.7.2-py3-none-any.whl |
|---|---|
| Size | 80.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
cba37089d393aea248fced00379a276dfa67544f0bd437d7f6476d389a080afb
|
|
BLAKE2b-256 checksum How to use checksums |
9688cdf87aa0a9f6fb04818308bcb240fcf176d60bb6f2d8787437cccea7bd2f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.13
|