Skip to content

OAC-4 (task D): node link allow non-loopback http origin behind allow_insecure_origin (rebase on main) - #11

Merged
sunyalou merged 1 commit into
mainfrom
oac-4/node-endpoint-v2
Oct 3, 2026
Merged

sunyalou merged 1 commit into
mainfrom
oac-4/node-endpoint-v2

Conversation

@sunyalou

@sunyalou sunyalou commented Oct 3, 2026

Copy link
Copy Markdown
Owner

目标

按 OAC-9 §3.1 任务 D,在最新 origin/main @ 3f0a737b(任务 B / PR #8 合入后)上重做 OAC-4 的 Core + 安装器部分(D1:register/ws)。制品下载放宽归 OAC-12,Web 命令归 OAC-8,均不在本 PR。

基线

origin/main @ 3f0a737b。本 PR 1 commit(a5a8ccea),未叠任何旧分支。

改动

Go(rebase PR #6 的 Go diff)

  • services/core/internal/sandbox/node/identity.go:StoredIdentity 新增 allow_insecure_origin(json:omitempty);InitIdentity 新增 allowInsecureOrigin bool;拆分 endpoint(默认契约不变)/ endpointAllowingInsecureOrigin / 唯一 validateEndpoint,新增 StoredIdentity.coreEndpoint。
  • enrollment.go、agent.go:Enroll/RefreshIdentity/Run/connect 一律按保留身份取策略。
  • cmd/sandbox-node/main.go:register 新增 --allow-insecure-origin;run 传该 flag 显式报错;core-url 帮助文本更新。
  • 测试:node_test.go(策略持久化、旧 identity.json 兼容、宽松变体边界、Enroll/RefreshIdentity 继承)、main_test.go(run 拒绝)、health_connection_linux_test.go(fixture 补 CoreURL)。
  • Go diff 与 PR OAC-4: node link allow non-loopback http origin behind allow_insecure_origin (A/B/D) #6 逐字节等价:git diff origin/main HEAD -- services/core/internal/sandbox/node services/core/cmd/sandbox-node 与 git diff e1e29049 e67c8680 -- <同路径> 的 sha256 相同(d6885aaa429651a092b1f07353c6643a29fef78de6cafd76c22596e70d3031e8)。PR OAC-4: node link allow non-loopback http origin behind allow_insecure_origin (A/B/D) #6 的 Go 部分已通过盲审 + 独立验证(OAC-4 2026-10-03 04:53 汇总),故 Go 部分不重复门禁。

安装器(新落点 deploy/node/)

  • deploy/node/node_install.py:origin(value, allow_insecure_origin=False) 放宽;解析器新增 --allow-insecure-origin(改为解析后校验,argparse type 看不到 flag);register argv 透传;根记录与 installation.json/registered.json 仅在 true 时写策略;node_record/wait_ready/重跑按策略比对。内容与 PR OAC-4: node link allow non-loopback http origin behind allow_insecure_origin (A/B/D) #6 的 deploy/install/node_install.py 逐字节相同(仅目录迁移)。
  • deploy/node/node_generations.py:401:prepare 改用保留身份(owned_root 读出的 identity)的 allow_insecure_origin 校验保留的 source_url,不再无条件要求 HTTPS。
  • 测试:test_node_install.py、test_node_readiness.py(同 PR OAC-4: node link allow non-loopback http origin behind allow_insecure_origin (A/B/D) #6)+ test_generation_review_regressions.py 新增 prepare 策略用例(严格拒绝 / 开关放行)。

不在本 PR 范围

  • deploy/node/distribution.py 下载链路放宽(OAC-12,backlog)。
  • apps/web/src/features/sandbox/enrollment-command.ts(OAC-8)。

验证(实跑)

  • go test ./services/core/internal/sandbox/node/ ./services/core/cmd/sandbox-node/ -count=1 → PASS
  • python3 -m unittest discover -s deploy/node → 131 tests,1 error(test_node_proxy openssl -addext,环境项)、2 skipped;本 PR 新增 7 用例全 PASS。
  • make check-core:sandbox/node、cmd/sandbox-node 通过;nativeinstaller FAIL 为环境项(curl 证书 / --max-time),baseline 3f0a737b 同样 FAIL。
  • make check-distribution:deploy/node discovery 1 error(同上 openssl);core-distribution-manifest.test.py 6 errors(缺 pigz,baseline 同样);其余 build-native-catalog、services/web、deploy/compose(5 OK)、scripts/acceptance(6 OK)、deploy/test_install.py(4 OK)、publish-core-release(38 OK)、bash -n、build-web.sh 全部通过。
  • make check-names → PASS
  • python3 scripts/ci_plan.py plan --base origin/main --head HEAD → hygiene / distribution / compose / backend / api
  • 环境项(nativeinstaller curl、openssl -addext、pigz)均在 clean baseline 3f0a737b 复现。

验收(本轮可独立验证部分)

  • 开关开时 http://IP 完成 register 并以 ws://IP 保持连接(Go 用例;PR OAC-4: node link allow non-loopback http origin behind allow_insecure_origin (A/B/D) #6 的独立验证已在非回环地址上端到端实测,本 PR Go diff 与之逐字节等价)。
  • services/core/internal/deployment/nodes.go 的 core_url == public_url 地址一致性未触碰。
  • 默认关闭时磁盘字节不变(identity.json omitempty;installation.json/registered.json/根记录仅 true 时写键)。
  • 不改动 TLS 证书校验、无 InsecureSkipVerify。
  • 一键安装端到端(制品下载)以 OAC-12 完成为前提,不在本 PR。

门禁

完成后停下等盲审 + 独立验证。

Rebase the Go part of the node-link change onto the post-refactor layout and
re-apply the installer change at deploy/node/. Retain the enrollment policy in
the node identity (identity.json allow_insecure_origin), validate it through a
single validateEndpoint rule with explicit endpoint variants, and read it back
on enroll/refresh/connect. The installer accepts --allow-insecure-origin,
records the policy only when opted in, forwards it to `oac-node register`, and
matches it on reruns and readiness. Generation preparation validates the
retained source_url under the retained identity's policy instead of always
requiring HTTPS. Default behavior and on-disk bytes are unchanged; TLS
certificate verification is never relaxed.

Baseline: origin/main @ 3f0a737. The Go diff is byte-identical to PR #6, whose
blind review and independent verification passed on the old baseline (OAC-4
2026-10-03 04:53 summary).

Tracks OAC-4 (task D).

Co-authored-by: multica-agent <github@multica.ai>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@sunyalou
sunyalou merged commit aedabbe into main Oct 3, 2026
18 checks passed
@sunyalou
sunyalou deleted the oac-4/node-endpoint-v2 branch October 4, 2026 10:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant