pub async fn run_events_daemon(db_path: &Path, socket_path: &Path) -> Result<()>Expand description
Serve the events daemon loop on socket_path, owning db_path.
Binds the socket (removing a stale path first), then accepts connections
for the process lifetime. Each connection is served sequentially:
same-uid admission, then a read-frame → dispatch → write-frame loop until
the peer disconnects. All storage goes through SqlEventStore on a
backend opened read-write against db_path; the events schema is ensured
once at boot.
Bind-path trust mirrors the main daemon socket: the socket directory must pass the same ownership/mode/swap-resistance validation, and the bound socket entry is chmod’d 0600 fail-closed. Pathname reachability is not identity — clients additionally verify the peer uid on every connect — but a hardened bind path is what keeps the bind itself out of another user’s hands.
This standalone entry resolves its environment once before opening the
daemon. Hosts with resolved policies use run_events_daemon_with_policies.