Skip to content

Node installer: allow plaintext artifact transfer behind allow_insecure_origin (OAC-12) - #13

Merged
sunyalou merged 1 commit into
mainfrom
oac-12/download-http-relax
Oct 3, 2026
Merged

sunyalou merged 1 commit into
mainfrom
oac-12/download-http-relax

Conversation

@sunyalou

@sunyalou sunyalou commented Oct 3, 2026

Copy link
Copy Markdown
Owner

目标

OAC-12 / OAC-9 任务 D2:allow_insecure_origin 打开且 public_url 为 http://IP 时,Web 一键安装的制品下载链路端到端打通(下载 → register → ws)。本 PR 只放宽制品传输层的 scheme,不新增开关归属。

改动

  • deploy/node/distribution.py:safe_url / ArtifactRedirect 增加 allow_insecure_origin 与同源约束;obtain_artifact / runtime_archive / download_partial / load_manifest 透传。开关关闭、或 URL 与配置 source_url 不同源时,行为与磁盘字节完全不变;禁 https→http 降级、禁跨 host http;重定向仍只转发 Range / If-Range;metadata 仍 NoRedirect;不引入 InsecureSkipVerify,TLS 证书校验不动。
  • deploy/node/node_install.py:prepare_runtime / register_node 的下载调用透传策略;开关打开时输出固定明文告警(无密钥)。
  • deploy/node/node_generations.py:prepare 从保留身份 identity.json.allow_insecure_origin 投影策略;runtime_files 透传。策略不写入 preparation.json,不新增第二套 env/文件回退。
  • services/core/cmd/sandbox-node/generations.go:抽出 helperArguments,runHelper 按 stored.AllowInsecureOrigin 给 generation helper 追加 --allow-insecure-origin。
  • 文档:deploy/node/README.md(download contract)、docs/getting-started/nodes.md(+zh)、docs/getting-started/self-hosted.md(+zh)、docs/configuration.md(+zh)、contracts/agents-api/node-generation-protocol.md(+zh,同步 frontmatter source_hash)。
  • 测试:test_distribution.py(scheme/redirect 策略、origin 归一化、obtain_artifact 投影)、test_node_generations.py(runtime_files 投影)、generations_test.go(helper 参数)。

验证

基线 origin/main @ aedabbe7;分支 oac-12/download-http-relax。

  • make check-names check-docs check-ci ✅
  • make check-harness-catalog ✅
  • make check-runtime-contract ✅
  • make check-website ✅(含 zh 翻译 source_hash 与 inline literal / fence 校验)
  • make build-core ✅;make check-core-packages:services/core/cmd/sandbox-node、services/core/internal/sandbox/node、services/core/internal/deployment 等全部 ✅
  • deploy/node 单测(含新增):test_distribution / test_node_generations / test_generation_review_regressions / test_node_helper_transfer / test_node_install / test_node_readiness / test_node_spec ✅;test_node_proxy 单独运行 ✅
  • python3 scripts/ci_plan.py plan --base origin/main --head HEAD → hygiene, distribution, compose, backend, website, api

环境性既有失败(非本 PR 引入,基线同样复现)

  • make check-distribution 中 python3 -m unittest discover -s deploy/node:test_node_proxy.setUpClass 的 openssl 失败。根因是 test_node_install 在进程内把 os.environ["PATH"] 设为 SAFE_PATH(node_install.py:994/1150),后续 openssl 解析到 /usr/bin/openssl 1.0.2k(不支持 -addext),而非环境的 OpenSSL 3.6.3。基线 origin/main 同样失败(同一错误)。
  • make check-core-packages / make check-go:services/core/internal/nativeinstaller(系统 curl 7.29.0/NSS 拒绝测试证书、--max-time 解析)与 apps/daemon/internal/{cli,daemonize}(daemon unavailable、StopPIDFile: function not implemented)失败;基线 origin/main 同样失败。
  • make check-core 的 check-core-store 需要 OAC_TEST_DATABASE_URL(本环境未提供);compose job 的 scripts/compose-smoke.py 需要 Docker。

已知限制

  • 未在本环境完成真实 http://IP 一键安装端到端(需要可用的开发部署 + Docker/PostgreSQL);已用单测覆盖 scheme / 同源 / 降级 / 跨 host / 重定向与策略投影。真实验收仍需在开发部署上跑 Web 生成的一键命令。
  • 未修改既有测试隔离缺陷(node_install.py 的 os.environ 变更泄漏),属无关改动。

关联

OAC-12;依据 OAC-9 §3.1 任务 D2 与 OAC-10 裁决。

…re_origin

Relax the node artifact transport scheme only when the retained allow_insecure_origin policy is on: safe_url and ArtifactRedirect admit plaintext HTTP only for the configured console origin, never an HTTPS downgrade and never another host. Thread the policy through obtain_artifact, runtime_archive, load_manifest, the installer call sites and the generation preparer, and pass it to the generation helper from sandbox-node. Default-off behavior is byte-for-byte unchanged.

Docs: node download contract, node guide, self-hosted requirements, configuration and the node generation protocol (en + zh). Tests: distribution scheme/redirect policy, generation runtime_files projection, helper arguments.
Co-authored-by: multica-agent <github@multica.ai>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@sunyalou
sunyalou merged commit 3dd86e5 into main Oct 3, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant