Repository navigation
Add nodes with a sudo command that reads the token from stdin - #148
Merged
Merged
Conversation
SaladDay
force-pushed
the
codex/web-node-sudo
branch
2 times, most recently
from
September 26, 2026 02:33
acfa91d to
ba78f3b
Compare
Add node now generates the sudo-mode command: a leading space, the checked installer run as root (sudo unless the shell is root) and the one-time token passed only on standard input. A "No sudo on this host?" disclosure gives the same command without sudo, with what the node's own user needs, and the log hint follows the mode on screen. The host requirements describe sudo mode. The dialog issues no command while the installation's public URL is loopback, and it reads the console configuration and the installation again on opening and on window focus, so a fix on the Core host shows without a reload. After Remove, a Clean up the host dialog gives the host's uninstall command in both forms.
…stale hosts in clean-up Add node now issues no command until the installation is read: it says it is checking, and a failed read blocks with Try again. The log hint follows the command last copied (with the system service's log after the no-sudo one, for a root shell), and a finished or restarted flow forgets it. The enrollment poll reads only the node list. The sudo checklist adds SELinux and names rootful Docker's docker group and /dev/kvm's kvm group; the no-sudo preparation is an administrator's one-time step, run from SSH or su. The clean-up dialog says it deletes no sandboxes, volumes or images (and keeps microsandbox's store), carries the loopback console note, and for a node enrolled with an earlier Core address offers the --force form. Closing it returns focus to the page heading. Copy buttons' names start with their visible text, and the command test proves the token goes through the shell's builtin printf.
SaladDay
force-pushed
the
codex/web-node-sudo
branch
from
September 26, 2026 04:19
ba78f3b to
c3581c9
Compare
SaladDay
added a commit
that referenced
this pull request
Sep 26, 2026
Web's Add node command passes the token on standard input in both modes (#148), and the Core installer no longer sets the variable (#152). The node installer now refuses the variable in every mode, with a one-line message naming --enrollment-token-stdin, instead of reading it. Standard input and the hidden prompt remain. A new node without a token is told to pass it on standard input. The operations upgrade table records the retirement.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Web part F2b of phase 2 (one-command node add), paired with the backend's node installer sudo mode (2b). Design:
20-phase2-node-design.md§2 and §8.Changes
--enrollment-token-stdin), so the token never appears in argv, the environment or sudo's log. It runs undersudounless already root. Every value isquote()d.machinectl shell, HOME length and the user-manager restart./dev/kvmplus microsandbox's libraries.parsar-nodeservice user and a system service and installs no software. On Docker,parsar-nodejoins the docker group, which is root-equivalent.sudo journalctl -u parsar-node-<id>.servicefor sudo mode,journalctl --user -u …for no-sudo mode.installation.local_only). Add node explains that nodes need a reachable HTTPSpublic_urland generates no command./console/configand the installation, so a "no node files" message clears after rerunning./install.sh.enrollment-command.tsexportsNodeInstallMode,nodeInstallCommand,nodeUninstallCommandandnodeLogCommand(§2.5).Tests
local_only, missing node files clearing without reload, and the clean-up dialog.Results: typecheck ✓, agents-client 601, web 366, build ✓, full web e2e 34/34.
Merge after the backend's 2b-node PR. The old command keeps working meanwhile.
docs/web (for the backend session's review)
protocol-coverage.md:120,:149,:151.Need help on this PR? Tag
@codesmithwith what you need. Autofix is disabled.