hop3-rootd
Privileged-operations agent for Hop3. Runs as root; exposes a narrow control-plane API to hop3-server (running unprivileged as the hop3 user) over a Unix domain socket.
See notes/adrs/041-privileged-operations-agent.md for the design rationale and notes/adrs/040-network-firewall-and-port-exposure.md for the firewall integration that motivated v1's op set.
What this is
hop3-rootd is the kernel-boundary executor for Hop3's runtime privileged actions. The unprivileged hop3-server reaches it via a Unix socket; rootd validates each request structurally, applies the privileged action (nftables mutation, nginx reload, etc.), and returns a typed result.
In v1 the operations are:
firewall.add_rule,firewall.remove_rule,firewall.list_rules— manage rules in a dedicatedinet hop3nftables table.nginx.reload,nginx.validate_config— wrap the privileged nginx commands previously granted tohop3-servervia/etc/sudoers.d/hop3(now retired).daemon.health,daemon.handshake— introspection.
What this is not
- A policy enforcement layer. SO_PEERCRED admits the
hop3user; structural validation rejects malformed requests. There is no per-op authorization, no policy file. Operator-level "did you mean this?" prompts live inhop3 deploy, not in rootd. - A general-purpose privileged-shell daemon. Rootd never accepts shell strings; every operation is a typed intent with a fixed argument schema.
Deployment
hop3-rootd ships as a stdlib-only Python package and is installed by hop3-installer alongside hop3-server. It runs as a hardened systemd unit (full ProtectX suite, CapabilityBoundingSet=CAP_NET_ADMIN, syscall filter, resource limits). The socket is at /run/hop3-rootd/socket, mode 0660, group hop3.
Development
# Run unit tests (no privileges needed)
pytest tests/a_unit/ -v
# Run integration tests (requires root + nftables)
sudo pytest tests/b_integration/ -v
# Lint
ruff check src tests
ruff format src tests
License
Apache-2.0 — Copyright (c) 2026, Abilian SAS
Metadata
Release files for hop3-rootd 0.7.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| hop3_rootd-0.7.3.tar.gz | 65.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| hop3_rootd-0.7.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 148.7 kB
Release files / hop3_rootd-0.7.3.tar.gz
| Download URL | hop3_rootd-0.7.3.tar.gz |
|---|---|
| Size | 65.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d595e057a50e2b7cea842eab9af21c95d13f6359420a6255359bea702182b644
|
|
BLAKE2b-256 checksum How to use checksums |
9ba5a1c8facad6fde00e60f786b673175c7123aa3df11356cd995f85d54dde1e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.13
|
Release files / hop3_rootd-0.7.3-py3-none-any.whl
| Download URL | hop3_rootd-0.7.3-py3-none-any.whl |
|---|---|
| Size | 83.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
59966047e6173847510ed8c3b9f55cb041386d5951e17429b8742c911ed9adaa
|
|
BLAKE2b-256 checksum How to use checksums |
d0867d258a2bc0311ff07b53b4dc422b64ca9982d686e789ede008face906b95
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.13
|