Node installer: allow plaintext artifact transfer behind allow_insecure_origin (OAC-12) - #13
Merged
Merged
Conversation
…re_origin Relax the node artifact transport scheme only when the retained allow_insecure_origin policy is on: safe_url and ArtifactRedirect admit plaintext HTTP only for the configured console origin, never an HTTPS downgrade and never another host. Thread the policy through obtain_artifact, runtime_archive, load_manifest, the installer call sites and the generation preparer, and pass it to the generation helper from sandbox-node. Default-off behavior is byte-for-byte unchanged. Docs: node download contract, node guide, self-hosted requirements, configuration and the node generation protocol (en + zh). Tests: distribution scheme/redirect policy, generation runtime_files projection, helper arguments. Co-authored-by: multica-agent <github@multica.ai>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
目标
OAC-12 / OAC-9 任务 D2:
allow_insecure_origin打开且public_url为http://IP时,Web 一键安装的制品下载链路端到端打通(下载 → register → ws)。本 PR 只放宽制品传输层的 scheme,不新增开关归属。改动
deploy/node/distribution.py:safe_url/ArtifactRedirect增加allow_insecure_origin与同源约束;obtain_artifact/runtime_archive/download_partial/load_manifest透传。开关关闭、或 URL 与配置source_url不同源时,行为与磁盘字节完全不变;禁 https→http 降级、禁跨 host http;重定向仍只转发Range/If-Range;metadata 仍NoRedirect;不引入InsecureSkipVerify,TLS 证书校验不动。deploy/node/node_install.py:prepare_runtime/register_node的下载调用透传策略;开关打开时输出固定明文告警(无密钥)。deploy/node/node_generations.py:prepare从保留身份identity.json.allow_insecure_origin投影策略;runtime_files透传。策略不写入preparation.json,不新增第二套 env/文件回退。services/core/cmd/sandbox-node/generations.go:抽出helperArguments,runHelper按stored.AllowInsecureOrigin给 generation helper 追加--allow-insecure-origin。deploy/node/README.md(download contract)、docs/getting-started/nodes.md(+zh)、docs/getting-started/self-hosted.md(+zh)、docs/configuration.md(+zh)、contracts/agents-api/node-generation-protocol.md(+zh,同步 frontmattersource_hash)。test_distribution.py(scheme/redirect 策略、origin 归一化、obtain_artifact投影)、test_node_generations.py(runtime_files投影)、generations_test.go(helper 参数)。验证
基线
origin/main @ aedabbe7;分支oac-12/download-http-relax。make check-names check-docs check-ci✅make check-harness-catalog✅make check-runtime-contract✅make check-website✅(含 zh 翻译source_hash与 inline literal / fence 校验)make build-core✅;make check-core-packages:services/core/cmd/sandbox-node、services/core/internal/sandbox/node、services/core/internal/deployment等全部 ✅deploy/node单测(含新增):test_distribution/test_node_generations/test_generation_review_regressions/test_node_helper_transfer/test_node_install/test_node_readiness/test_node_spec✅;test_node_proxy单独运行 ✅python3 scripts/ci_plan.py plan --base origin/main --head HEAD→ hygiene, distribution, compose, backend, website, api环境性既有失败(非本 PR 引入,基线同样复现)
make check-distribution中python3 -m unittest discover -s deploy/node:test_node_proxy.setUpClass的openssl失败。根因是test_node_install在进程内把os.environ["PATH"]设为SAFE_PATH(node_install.py:994/1150),后续openssl解析到/usr/bin/openssl1.0.2k(不支持-addext),而非环境的 OpenSSL 3.6.3。基线origin/main同样失败(同一错误)。make check-core-packages/make check-go:services/core/internal/nativeinstaller(系统 curl 7.29.0/NSS 拒绝测试证书、--max-time解析)与apps/daemon/internal/{cli,daemonize}(daemon unavailable、StopPIDFile: function not implemented)失败;基线origin/main同样失败。make check-core的check-core-store需要OAC_TEST_DATABASE_URL(本环境未提供);compose job 的scripts/compose-smoke.py需要 Docker。已知限制
http://IP一键安装端到端(需要可用的开发部署 + Docker/PostgreSQL);已用单测覆盖 scheme / 同源 / 降级 / 跨 host / 重定向与策略投影。真实验收仍需在开发部署上跑 Web 生成的一键命令。node_install.py的os.environ变更泄漏),属无关改动。关联
OAC-12;依据 OAC-9 §3.1 任务 D2 与 OAC-10 裁决。