Skip to content

OAC-13: fix(installer): check the configuration before starting a fresh install - #12

Merged
sunyalou merged 1 commit into
mainfrom
fix/oac13-install-check-config
Oct 3, 2026
Merged

sunyalou merged 1 commit into
mainfrom
fix/oac13-install-check-config

Conversation

@sunyalou

@sunyalou sunyalou commented Oct 3, 2026

Copy link
Copy Markdown
Owner

目标

全新安装路径在 Core 拒绝配置时不得谎报成功。当前 deploy/install.sh 的序列是 compose pull → create core → cp → up -d --wait,不先校验配置;Core 在 processconfig.Check() 处 exit 1 后由 restart: unless-stopped 反复重启,而 --wait 仍返回 0,脚本随即打印 OpenAgentCore is running.。本 PR 让安装脚本在启动服务栈之前完成数据初始化并校验配置,失败即非零退出、给出 Core 的原文案,并由 cleanup trap 删除安装目录。

改动

  • deploy/install.sh:在 up -d --wait 之前依次执行
    • docker compose run --rm -T init:把 init 跑到完成,写入 installation.id、密钥等(check-config 会读这些文件);
    • docker compose run --rm -T --no-deps --entrypoint /usr/local/bin/oac-core core check-config:与 oac apply(services/core/cmd/oac/main.go:102)同形;
    • 任一步失败:把捕获到的输出(含 Core 原文案)与一句摘要打到 stderr,非零退出,cleanup trap 删除目录;成功才 up -d --wait。
    • 捕获输出是为了成功路径的输出与文案逐字不变(init 与 check-config 的进度/日志不外泄)。
  • deploy/test_install.py:桩 docker 支持 compose run,新增 4 个用例(顺序、拒绝、开关打开仍成功、init 失败即停)。
  • deploy/README.md:补一句说明安装脚本会先初始化并校验配置。

验证命令与结果

本地环境:Go 1.26.6、Docker Compose v2.26.1、Python 3.11.16(无外网,ghcr 不可达;Go 模块缓存可用)。

  • bash -n deploy/install.sh → OK
  • python3 deploy/test_install.py → 8 tests OK(原 4 + 新 4)
  • python3 -m unittest discover -s deploy/compose -p 'test_*.py' → 5 tests OK
  • make check-names → 15 tests OK,name guard passed
  • make check-docs check-ci → 6 + 46 tests OK
  • make check-harness-catalog → 5 tests OK
  • python3 scripts/ci_plan.py plan --base origin/main --head HEAD → hygiene, distribution
  • 真实 oac-core check-config(go build ./services/core/cmd/server,go1.26.6):
    • OAC_PUBLIC_URL=http://10.0.0.5:8080(开关关)→ exit 1,stderr 原文案 … plain HTTP is accepted only for a loopback host
    • 同 URL + OAC_ALLOW_INSECURE_ORIGIN=1 → exit 0
    • OAC_PUBLIC_URL=https://core.example → exit 0
    • 合法 https 但 OAC_INSTALLATION_ID_FILE 指向不存在文件 → exit 1 OAC_INSTALLATION_ID_FILE must name a readable file(证明必须先跑 init)
  • 端到端(桩 docker 实际 exec 真实 oac-core,走真实 install.sh):
    • 开关关 + http://10.0.0.5:8080:exit 1,stderr 为原文案 + Configuration check failed; no service was started.,stdout 为空(不打印 OpenAgentCore is running.),安装目录已删除
    • 开关开 + http://10.0.0.5:8080:exit 0,成功横幅与改动前逐字一致,目录保留
    • https://core.example:exit 0,成功横幅逐字一致
    • 调用顺序日志:init → check-config → up -d --wait(失败时为 init → check-config → down --remove-orphans)

已知限制 / 决策记录

  • make check-distribution 在本沙箱有两个既有、无关子测试失败:scripts/core-distribution-manifest.test.py 缺 pigz,deploy/node/test_node_proxy.py 的 openssl -addext 调用失败。二者在未改动的基线 origin/main@54ce8d0d 上同样失败;CI 的 distribution job 会 apt-get install pigz,故应在 CI 通过。其余子测试(node catalog、go test ./services/web、deploy/compose、deploy/test_install、publish-core-release、bash -n、build-web、scripts/acceptance)本地均通过。
  • 选用 docker compose run --rm init 而非 up -d --wait init:实测(compose 2.26.1)up -d --wait init 即使 init exit 0 也返回 rc=1(--wait 把已退出的 one-shot 视为未就绪),无法用作前置门;run 会阻塞并返回 init 的退出码。
  • deploy/install.dev.sh(开发者本地 checkout 路径)按范围要求未改,仍存在同样的假成功风险;它不是发布版安装路径。
  • docs/getting-started/install.md 的步骤列表未改(其“starts the services with Docker Compose”描述仍成立),改为在 deploy/README.md 记录新增的校验步骤,以避免触碰需同步 source_hash 的翻译链。若需要,可在后续 PR 补。
  • 未改 TLS 校验,未引入 InsecureSkipVerify。

门禁

请 @oac 队长 安排盲审与独立验证;不自行合并、不标 done。

A fresh install ran compose pull, created the Core container to copy oac
out, then started the stack with up -d --wait. Core exits on an invalid
configuration and restarts forever, yet --wait still returns 0, so the
installer printed 'OpenAgentCore is running.' while Core was not
listening.

install.sh now runs the data initialization to completion and validates
the settings with oac-core check-config before up -d --wait, matching
oac apply. check-config reads the installation id that init writes, so
init must run first; a rejected configuration exits non-zero, prints the
Core message, and the cleanup trap removes the directory.

Co-authored-by: multica-agent <github@multica.ai>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@sunyalou sunyalou changed the title fix(installer): check the configuration before starting a fresh install OAC-13: fix(installer): check the configuration before starting a fresh install Oct 3, 2026
@sunyalou
sunyalou merged commit 836c7ef into main Oct 3, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant