OAC-4 (task D): node link allow non-loopback http origin behind allow_insecure_origin (rebase on main) - #11
Merged
Merged
Conversation
Rebase the Go part of the node-link change onto the post-refactor layout and re-apply the installer change at deploy/node/. Retain the enrollment policy in the node identity (identity.json allow_insecure_origin), validate it through a single validateEndpoint rule with explicit endpoint variants, and read it back on enroll/refresh/connect. The installer accepts --allow-insecure-origin, records the policy only when opted in, forwards it to `oac-node register`, and matches it on reruns and readiness. Generation preparation validates the retained source_url under the retained identity's policy instead of always requiring HTTPS. Default behavior and on-disk bytes are unchanged; TLS certificate verification is never relaxed. Baseline: origin/main @ 3f0a737. The Go diff is byte-identical to PR #6, whose blind review and independent verification passed on the old baseline (OAC-4 2026-10-03 04:53 summary). Tracks OAC-4 (task D). Co-authored-by: multica-agent <github@multica.ai>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
目标
按 OAC-9 §3.1 任务 D,在最新
origin/main @ 3f0a737b(任务 B / PR #8 合入后)上重做 OAC-4 的 Core + 安装器部分(D1:register/ws)。制品下载放宽归 OAC-12,Web 命令归 OAC-8,均不在本 PR。基线
origin/main @ 3f0a737b。本 PR 1 commit(a5a8ccea),未叠任何旧分支。改动
Go(rebase PR #6 的 Go diff)
services/core/internal/sandbox/node/identity.go:StoredIdentity新增allow_insecure_origin(json:omitempty);InitIdentity新增allowInsecureOrigin bool;拆分endpoint(默认契约不变)/endpointAllowingInsecureOrigin/ 唯一validateEndpoint,新增StoredIdentity.coreEndpoint。enrollment.go、agent.go:Enroll/RefreshIdentity/Run/connect一律按保留身份取策略。cmd/sandbox-node/main.go:register新增--allow-insecure-origin;run传该 flag 显式报错;core-url帮助文本更新。node_test.go(策略持久化、旧identity.json兼容、宽松变体边界、Enroll/RefreshIdentity继承)、main_test.go(run 拒绝)、health_connection_linux_test.go(fixture 补CoreURL)。git diff origin/main HEAD -- services/core/internal/sandbox/node services/core/cmd/sandbox-node与git diff e1e29049 e67c8680 -- <同路径>的 sha256 相同(d6885aaa429651a092b1f07353c6643a29fef78de6cafd76c22596e70d3031e8)。PR OAC-4: node link allow non-loopback http origin behind allow_insecure_origin (A/B/D) #6 的 Go 部分已通过盲审 + 独立验证(OAC-4 2026-10-03 04:53 汇总),故 Go 部分不重复门禁。安装器(新落点
deploy/node/)deploy/node/node_install.py:origin(value, allow_insecure_origin=False)放宽;解析器新增--allow-insecure-origin(改为解析后校验,argparsetype看不到 flag);registerargv 透传;根记录与installation.json/registered.json仅在 true 时写策略;node_record/wait_ready/重跑按策略比对。内容与 PR OAC-4: node link allow non-loopback http origin behind allow_insecure_origin (A/B/D) #6 的deploy/install/node_install.py逐字节相同(仅目录迁移)。deploy/node/node_generations.py:401:prepare改用保留身份(owned_root读出的identity)的allow_insecure_origin校验保留的source_url,不再无条件要求 HTTPS。test_node_install.py、test_node_readiness.py(同 PR OAC-4: node link allow non-loopback http origin behind allow_insecure_origin (A/B/D) #6)+test_generation_review_regressions.py新增 prepare 策略用例(严格拒绝 / 开关放行)。不在本 PR 范围
deploy/node/distribution.py下载链路放宽(OAC-12,backlog)。apps/web/src/features/sandbox/enrollment-command.ts(OAC-8)。验证(实跑)
go test ./services/core/internal/sandbox/node/ ./services/core/cmd/sandbox-node/ -count=1→ PASSpython3 -m unittest discover -s deploy/node→ 131 tests,1 error(test_node_proxyopenssl-addext,环境项)、2 skipped;本 PR 新增 7 用例全 PASS。make check-core:sandbox/node、cmd/sandbox-node通过;nativeinstallerFAIL 为环境项(curl 证书 /--max-time),baseline3f0a737b同样 FAIL。make check-distribution:deploy/nodediscovery 1 error(同上 openssl);core-distribution-manifest.test.py6 errors(缺pigz,baseline 同样);其余build-native-catalog、services/web、deploy/compose(5 OK)、scripts/acceptance(6 OK)、deploy/test_install.py(4 OK)、publish-core-release(38 OK)、bash -n、build-web.sh全部通过。make check-names→ PASSpython3 scripts/ci_plan.py plan --base origin/main --head HEAD→hygiene / distribution / compose / backend / api-addext、pigz)均在 clean baseline3f0a737b复现。验收(本轮可独立验证部分)
http://IP完成 register 并以ws://IP保持连接(Go 用例;PR OAC-4: node link allow non-loopback http origin behind allow_insecure_origin (A/B/D) #6 的独立验证已在非回环地址上端到端实测,本 PR Go diff 与之逐字节等价)。services/core/internal/deployment/nodes.go的core_url == public_url地址一致性未触碰。identity.jsonomitempty;installation.json/registered.json/根记录仅 true 时写键)。InsecureSkipVerify。门禁
完成后停下等盲审 + 独立验证。