Conversation
Retain the enrollment policy in the node identity (identity.json allow_insecure_origin), validate it through one validateEndpoint rule with explicit endpoint variants, and read it back on every enroll/refresh/connect. The installer accepts --allow-insecure-origin, records the policy in its state and root records, forwards it to `oac-node register`, and matches it on reruns and readiness checks. Default behavior and on-disk bytes are unchanged; TLS certificate verification is never relaxed. Baseline: OAC-2 feat/allow-insecure-origin (e1e2904). Tracks OAC-4. Co-authored-by: multica-agent <github@multica.ai>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e67c868009
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if args.allow_insecure_origin: | ||
| # Only an opted-in installation records the policy, so a default node's | ||
| # installation.json and registered.json stay byte-for-byte unchanged. | ||
| state["allow_insecure_origin"] = True |
There was a problem hiding this comment.
Keep insecure-origin policy in one record
When --allow-insecure-origin is enabled, this policy is persisted in installation.json and registered.json, while the node also persists and consumes it from identity.json and sudo mode keeps another copy in its root record. Those independent copies are subsequently validated on reruns and readiness checks, creating multiple sources of truth for a single connection policy; retain it only in the identity and derive the installer checks from there.
AGENTS.md reference: AGENTS.md:L46-L46
Useful? React with 👍 / 👎.
|
失效关闭:base 为已失效的 PR #2 分支,且安装器/文档部分需剔除。Go 部分由 OAC-4 任务 D 基于 origin/main 重做后新开 PR(分支 |
目标
实现 OAC-4 的 A/B/D 三部分:节点在非 loopback
http://IP上完成register并以ws://IP保持连接(开关开时),默认关闭行为与现状完全一致,且不改动 TLS 证书校验。改动
A. Go(
services/core)internal/sandbox/node/identity.goStoredIdentity新增allow_insecure_origin(jsontagomitempty;默认 false 时identity.json字节不变)。InitIdentity新增allowInsecureOrigin bool参数;initIdentity用它校验core_url、写入身份,并把策略并入重跑一致性比较。endpoint(默认契约不变)/endpointAllowingInsecureOrigin/ 唯一实现validateEndpoint(raw, path, allowInsecureOrigin);新增StoredIdentity.coreEndpoint(path)按保留身份取策略,endpoint内无 env/别名/URL 推断。internal/sandbox/node/enrollment.go:Enroll、RefreshIdentity改用stored.coreEndpoint(...)。internal/sandbox/node/agent.go:Run、connect改用stored.coreEndpoint(...)(AgentConfig不变)。cmd/sandbox-node/main.go:register新增--allow-insecure-origin;run传该 flag 时显式报错;core-url帮助文本更新。node_test.go增策略持久化、旧identity.json(缺字段)兼容、宽松变体边界、Enroll/RefreshIdentity继承策略;main_test.go增run拒绝用例;health_connection_linux_test.gofixture 补CoreURL(生产Run必读该字段)。B. 安装器(
deploy/install/node_install.py)origin(value, allow_insecure_origin=False):开关开时允许非 loopbackhttp,凭据/query/path/非 http scheme 仍拒。--source-url/--core-url改为解析后校验(argparsetype看不到 flag),新增--allow-insecure-origin(store_true)。registerargv 在开关开时追加--allow-insecure-origin。installation.json/registered.json仅在为 true 时写入allow_insecure_origin(默认安装与存量 marker 字节不变);node_record用记录自带策略校验地址;重跑比对策略;wait_ready比对保留身份策略。test_node_install.py、test_node_readiness.py新增开关放行/默认拒绝、register 透传、默认不写策略、记录策略校验、readiness 策略比对。D. 文档
contracts/agents-api/node-generation-protocol.md(+ zh):Connection 步骤 1 补充「保留身份策略允许时ws://非 loopback」。docs/getting-started/nodes.md(+ zh):手动注册示例说明--allow-insecure-origin(仅开发/测试、明文风险),并更新 zhsource_hash。基线
feat/allow-insecure-origin@e1e29049(OAC-2)。PR base 指向该分支以隔离本 issue diff。验证(实跑)
go test ./services/core/internal/sandbox/node/ ./services/core/cmd/sandbox-node/ -count=1:PASSpython3 -m unittest test_node_install test_node_readiness:73 tests OKnode --test website/tests/translations.test.mjs(含source_hash与 inline-literal 校验):3 tests PASSmake check-names:PASSmake check-core:build-core通过;check-core-packages中本 issue 相关包(sandbox/node、cmd/sandbox-node)通过;services/core/internal/nativeinstaller在 clean baseline28d34ff0上同样失败(环境:curl证书策略 /--max-time版本),与本次改动无关;check-core-store因未设置OAC_TEST_DATABASE_URL未运行。make check-distribution:node --test scripts/build-native-catalog.test.mjs、config-reference.py --check、publish-core-release.test.py、install-release.test.py、bash -n、build-web.sh通过;deploy/installdiscovery 242 tests 中仅test_node_proxy的 openssl-addext环境错误(baseline 同样失败),go test ./services/web因 Unix socket 路径过长bind: invalid argument(baseline 同样失败),core-distribution-manifest.test.py因缺少pigz(baseline 同样失败)。已知限制 / 需裁决
deploy/install/distribution.py的safe_url(及ArtifactRedirect)对 metadata/artifact 下载强制 HTTPS,且node_generations.py:401用严格origin()校验保留的source_url。因此--source-url http://IP的完整安装仍会在下载阶段失败——架构裁决第 9 条假设「下载由 curl 完成」,实测并非如此(安装器自行下载节点文件)。是否放宽distribution.py(含重定向策略)以及 generation 准备路径的策略来源,需单独裁决;本 PR 按派发范围只改node_install.py。oac-node register --allow-insecure-origin+run(A 部分)已可满足「http 注册、ws 连接」;上述限制只影响通过安装器的一键流程。门禁
完成后停下等独立审查与测试验证。