OAC-13: fix(installer): check the configuration before starting a fresh install - #12
Merged
Merged
Conversation
A fresh install ran compose pull, created the Core container to copy oac out, then started the stack with up -d --wait. Core exits on an invalid configuration and restarts forever, yet --wait still returns 0, so the installer printed 'OpenAgentCore is running.' while Core was not listening. install.sh now runs the data initialization to completion and validates the settings with oac-core check-config before up -d --wait, matching oac apply. check-config reads the installation id that init writes, so init must run first; a rejected configuration exits non-zero, prints the Core message, and the cleanup trap removes the directory. Co-authored-by: multica-agent <github@multica.ai>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
目标
全新安装路径在 Core 拒绝配置时不得谎报成功。当前
deploy/install.sh的序列是compose pull → create core → cp → up -d --wait,不先校验配置;Core 在processconfig.Check()处 exit 1 后由restart: unless-stopped反复重启,而--wait仍返回 0,脚本随即打印OpenAgentCore is running.。本 PR 让安装脚本在启动服务栈之前完成数据初始化并校验配置,失败即非零退出、给出 Core 的原文案,并由 cleanup trap 删除安装目录。改动
deploy/install.sh:在up -d --wait之前依次执行docker compose run --rm -T init:把init跑到完成,写入installation.id、密钥等(check-config会读这些文件);docker compose run --rm -T --no-deps --entrypoint /usr/local/bin/oac-core core check-config:与oac apply(services/core/cmd/oac/main.go:102)同形;up -d --wait。init与check-config的进度/日志不外泄)。deploy/test_install.py:桩docker支持compose run,新增 4 个用例(顺序、拒绝、开关打开仍成功、init 失败即停)。deploy/README.md:补一句说明安装脚本会先初始化并校验配置。验证命令与结果
本地环境:Go 1.26.6、Docker Compose v2.26.1、Python 3.11.16(无外网,ghcr 不可达;Go 模块缓存可用)。
bash -n deploy/install.sh→ OKpython3 deploy/test_install.py→ 8 tests OK(原 4 + 新 4)python3 -m unittest discover -s deploy/compose -p 'test_*.py'→ 5 tests OKmake check-names→ 15 tests OK,name guard passedmake check-docs check-ci→ 6 + 46 tests OKmake check-harness-catalog→ 5 tests OKpython3 scripts/ci_plan.py plan --base origin/main --head HEAD→hygiene,distributionoac-core check-config(go build ./services/core/cmd/server,go1.26.6):OAC_PUBLIC_URL=http://10.0.0.5:8080(开关关)→ exit 1,stderr 原文案… plain HTTP is accepted only for a loopback hostOAC_ALLOW_INSECURE_ORIGIN=1→ exit 0OAC_PUBLIC_URL=https://core.example→ exit 0OAC_INSTALLATION_ID_FILE指向不存在文件 → exit 1OAC_INSTALLATION_ID_FILE must name a readable file(证明必须先跑init)docker实际 exec 真实oac-core,走真实install.sh):http://10.0.0.5:8080:exit 1,stderr 为原文案 +Configuration check failed; no service was started.,stdout 为空(不打印OpenAgentCore is running.),安装目录已删除http://10.0.0.5:8080:exit 0,成功横幅与改动前逐字一致,目录保留https://core.example:exit 0,成功横幅逐字一致init → check-config → up -d --wait(失败时为init → check-config → down --remove-orphans)已知限制 / 决策记录
make check-distribution在本沙箱有两个既有、无关子测试失败:scripts/core-distribution-manifest.test.py缺pigz,deploy/node/test_node_proxy.py的 openssl-addext调用失败。二者在未改动的基线origin/main@54ce8d0d上同样失败;CI 的 distribution job 会apt-get install pigz,故应在 CI 通过。其余子测试(node catalog、go test ./services/web、deploy/compose、deploy/test_install、publish-core-release、bash -n、build-web、scripts/acceptance)本地均通过。docker compose run --rm init而非up -d --wait init:实测(compose 2.26.1)up -d --wait init即使initexit 0 也返回 rc=1(--wait把已退出的 one-shot 视为未就绪),无法用作前置门;run会阻塞并返回 init 的退出码。deploy/install.dev.sh(开发者本地 checkout 路径)按范围要求未改,仍存在同样的假成功风险;它不是发布版安装路径。docs/getting-started/install.md的步骤列表未改(其“starts the services with Docker Compose”描述仍成立),改为在deploy/README.md记录新增的校验步骤,以避免触碰需同步source_hash的翻译链。若需要,可在后续 PR 补。InsecureSkipVerify。门禁
请 @oac 队长 安排盲审与独立验证;不自行合并、不标 done。