Skip to content

Add nodes with a sudo command that reads the token from stdin - #148

Merged
SaladDay merged 4 commits into
mainfrom
codex/web-node-sudo
Sep 26, 2026
Merged

SaladDay merged 4 commits into
mainfrom
codex/web-node-sudo

Conversation

@SaladDay

@SaladDay SaladDay commented Sep 26, 2026 •

Copy link
Copy Markdown
Collaborator

Web part F2b of phase 2 (one-command node add), paired with the backend's node installer sudo mode (2b). Design: 20-phase2-node-design.md §2 and §8.

Changes

  • Add node command: sudo mode by default. It starts with a space, so shell history skips it. It downloads and checks the installer as before, then pipes the token on stdin (--enrollment-token-stdin), so the token never appears in argv, the environment or sudo's log. It runs under sudo unless already root. Every value is quote()d.
    • A collapsed "No sudo on this host?" section holds the non-root command and the old preparation steps: group membership, lingering, machinectl shell, HOME length and the user-manager restart.
  • Host requirements (sudo mode).
    • Linux amd64 with systemd; Python 3.9+, curl and sha256sum; root or sudo.
    • Docker Engine enforcing limits (cgroup v2), or /dev/kvm plus microsandbox's libraries.
    • CPU and memory for one sandbox, and about 2 GB of disk.
    • The host reaches the console and Core; sandboxes reach Core.
    • Notes: the command creates the parsar-node service user and a system service and installs no software. On Docker, parsar-node joins the docker group, which is root-equivalent.
  • Log hint. It follows the mode shown: sudo journalctl -u parsar-node-<id>.service for sudo mode, journalctl --user -u … for no-sudo mode.
  • After Remove. A Clean up the host dialog shows the uninstall command, with the no-sudo variant collapsed.
  • Loopback installs (installation.local_only). Add node explains that nodes need a reachable HTTPS public_url and generates no command.
  • Freshness. Opening the dialog, or refocusing the window while it's open, rereads /console/config and the installation, so a "no node files" message clears after rerunning ./install.sh.

enrollment-command.ts exports NodeInstallMode, nodeInstallCommand, nodeUninstallCommand and nodeLogCommand (§2.5).

Tests

  • Unit tests pin the exact command texts. A fake-shell test runs them and proves the token arrives only on stdin, never in the installer's or sudo's arguments or environment. It also covers the root shell and every failure branch.
  • e2e covers the sudo requirements and command, the no-sudo section and log hint, local_only, missing node files clearing without reload, and the clean-up dialog.

Results: typecheck ✓, agents-client 601, web 366, build ✓, full web e2e 34/34.

Merge after the backend's 2b-node PR. The old command keeps working meanwhile.

docs/web (for the backend session's review)

protocol-coverage.md:120, :149, :151.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith with what you need. Autofix is disabled.

Add node now generates the sudo-mode command: a leading space, the checked
installer run as root (sudo unless the shell is root) and the one-time token
passed only on standard input. A "No sudo on this host?" disclosure gives the
same command without sudo, with what the node's own user needs, and the log hint
follows the mode on screen. The host requirements describe sudo mode. The dialog
issues no command while the installation's public URL is loopback, and it reads
the console configuration and the installation again on opening and on window
focus, so a fix on the Core host shows without a reload. After Remove, a Clean
up the host dialog gives the host's uninstall command in both forms.
…stale hosts in clean-up

Add node now issues no command until the installation is read: it says it is
checking, and a failed read blocks with Try again. The log hint follows the
command last copied (with the system service's log after the no-sudo one, for a
root shell), and a finished or restarted flow forgets it. The enrollment poll
reads only the node list. The sudo checklist adds SELinux and names rootful
Docker's docker group and /dev/kvm's kvm group; the no-sudo preparation is an
administrator's one-time step, run from SSH or su.

The clean-up dialog says it deletes no sandboxes, volumes or images (and keeps
microsandbox's store), carries the loopback console note, and for a node enrolled
with an earlier Core address offers the --force form. Closing it returns focus to
the page heading. Copy buttons' names start with their visible text, and the
command test proves the token goes through the shell's builtin printf.
@SaladDay
SaladDay merged commit ffb4ad5 into main Sep 26, 2026
2 checks passed
SaladDay added a commit that referenced this pull request Sep 26, 2026
Web's Add node command passes the token on standard input in both modes (#148),
and the Core installer no longer sets the variable (#152). The node installer
now refuses the variable in every mode, with a one-line message naming
--enrollment-token-stdin, instead of reading it. Standard input and the hidden
prompt remain. A new node without a token is told to pass it on standard input.
The operations upgrade table records the retirement.
@SaladDay
SaladDay deleted the codex/web-node-sudo branch October 7, 2026 06:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant