Skip to content

OAC-4: node link allow non-loopback http origin behind allow_insecure_origin (A/B/D) - #6

Closed
sunyalou wants to merge 1 commit into
feat/allow-insecure-originfrom
oac-4/node-endpoint
Closed

sunyalou wants to merge 1 commit into
feat/allow-insecure-originfrom
oac-4/node-endpoint

Conversation

@sunyalou

@sunyalou sunyalou commented Oct 3, 2026

Copy link
Copy Markdown
Owner

目标

实现 OAC-4 的 A/B/D 三部分:节点在非 loopback http://IP 上完成 register 并以 ws://IP 保持连接(开关开时),默认关闭行为与现状完全一致,且不改动 TLS 证书校验。

改动

A. Go(services/core)

  • internal/sandbox/node/identity.go
    • StoredIdentity 新增 allow_insecure_origin(json tag omitempty;默认 false 时 identity.json 字节不变)。
    • InitIdentity 新增 allowInsecureOrigin bool 参数;initIdentity 用它校验 core_url、写入身份,并把策略并入重跑一致性比较。
    • 拆分 endpoint(默认契约不变)/ endpointAllowingInsecureOrigin / 唯一实现 validateEndpoint(raw, path, allowInsecureOrigin);新增 StoredIdentity.coreEndpoint(path) 按保留身份取策略,endpoint 内无 env/别名/URL 推断。
  • internal/sandbox/node/enrollment.go:Enroll、RefreshIdentity 改用 stored.coreEndpoint(...)。
  • internal/sandbox/node/agent.go:Run、connect 改用 stored.coreEndpoint(...)(AgentConfig 不变)。
  • cmd/sandbox-node/main.go:register 新增 --allow-insecure-origin;run 传该 flag 时显式报错;core-url 帮助文本更新。
  • 测试:node_test.go 增策略持久化、旧 identity.json(缺字段)兼容、宽松变体边界、Enroll/RefreshIdentity 继承策略;main_test.go 增 run 拒绝用例;health_connection_linux_test.go fixture 补 CoreURL(生产 Run 必读该字段)。

B. 安装器(deploy/install/node_install.py)

  • origin(value, allow_insecure_origin=False):开关开时允许非 loopback http,凭据/query/path/非 http scheme 仍拒。
  • 解析器:--source-url/--core-url 改为解析后校验(argparse type 看不到 flag),新增 --allow-insecure-origin(store_true)。
  • register argv 在开关开时追加 --allow-insecure-origin。
  • 根记录与 installation.json/registered.json 仅在为 true 时写入 allow_insecure_origin(默认安装与存量 marker 字节不变);node_record 用记录自带策略校验地址;重跑比对策略;wait_ready 比对保留身份策略。
  • 测试:test_node_install.py、test_node_readiness.py 新增开关放行/默认拒绝、register 透传、默认不写策略、记录策略校验、readiness 策略比对。

D. 文档

  • contracts/agents-api/node-generation-protocol.md(+ zh):Connection 步骤 1 补充「保留身份策略允许时 ws:// 非 loopback」。
  • docs/getting-started/nodes.md(+ zh):手动注册示例说明 --allow-insecure-origin(仅开发/测试、明文风险),并更新 zh source_hash。
  • 与 OAC-2 重叠的「Before you add a node」段落已由 OAC-2 在本 PR 基线中修改,本 PR 未重复改动。

基线

feat/allow-insecure-origin @ e1e29049(OAC-2)。PR base 指向该分支以隔离本 issue diff。

验证(实跑)

  • go test ./services/core/internal/sandbox/node/ ./services/core/cmd/sandbox-node/ -count=1:PASS
  • python3 -m unittest test_node_install test_node_readiness:73 tests OK
  • node --test website/tests/translations.test.mjs(含 source_hash 与 inline-literal 校验):3 tests PASS
  • make check-names:PASS
  • make check-core:build-core 通过;check-core-packages 中本 issue 相关包(sandbox/node、cmd/sandbox-node)通过;services/core/internal/nativeinstaller 在 clean baseline 28d34ff0 上同样失败(环境:curl 证书策略 / --max-time 版本),与本次改动无关;check-core-store 因未设置 OAC_TEST_DATABASE_URL 未运行。
  • make check-distribution:node --test scripts/build-native-catalog.test.mjs、config-reference.py --check、publish-core-release.test.py、install-release.test.py、bash -n、build-web.sh 通过;deploy/install discovery 242 tests 中仅 test_node_proxy 的 openssl -addext 环境错误(baseline 同样失败),go test ./services/web 因 Unix socket 路径过长 bind: invalid argument(baseline 同样失败),core-distribution-manifest.test.py 因缺少 pigz(baseline 同样失败)。

已知限制 / 需裁决

  • 安装器下载链路仍被 HTTPS 卡住:deploy/install/distribution.py 的 safe_url(及 ArtifactRedirect)对 metadata/artifact 下载强制 HTTPS,且 node_generations.py:401 用严格 origin() 校验保留的 source_url。因此 --source-url http://IP 的完整安装仍会在下载阶段失败——架构裁决第 9 条假设「下载由 curl 完成」,实测并非如此(安装器自行下载节点文件)。是否放宽 distribution.py(含重定向策略)以及 generation 准备路径的策略来源,需单独裁决;本 PR 按派发范围只改 node_install.py。
  • 手动 oac-node register --allow-insecure-origin + run(A 部分)已可满足「http 注册、ws 连接」;上述限制只影响通过安装器的一键流程。

门禁

完成后停下等独立审查与测试验证。

Retain the enrollment policy in the node identity (identity.json
allow_insecure_origin), validate it through one validateEndpoint rule with
explicit endpoint variants, and read it back on every enroll/refresh/connect.
The installer accepts --allow-insecure-origin, records the policy in its state
and root records, forwards it to `oac-node register`, and matches it on reruns
and readiness checks. Default behavior and on-disk bytes are unchanged; TLS
certificate verification is never relaxed.

Baseline: OAC-2 feat/allow-insecure-origin (e1e2904).
Tracks OAC-4.

Co-authored-by: multica-agent <github@multica.ai>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e67c868009

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +400 to +403
if args.allow_insecure_origin:
# Only an opted-in installation records the policy, so a default node's
# installation.json and registered.json stay byte-for-byte unchanged.
state["allow_insecure_origin"] = True

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Keep insecure-origin policy in one record

When --allow-insecure-origin is enabled, this policy is persisted in installation.json and registered.json, while the node also persists and consumes it from identity.json and sudo mode keeps another copy in its root record. Those independent copies are subsequently validated on reruns and readiness checks, creating multiple sources of truth for a single connection policy; retain it only in the identity and derive the installer checks from there.

AGENTS.md reference: AGENTS.md:L46-L46

Useful? React with 👍 / 👎.

@sunyalou

sunyalou commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

失效关闭:base 为已失效的 PR #2 分支,且安装器/文档部分需剔除。Go 部分由 OAC-4 任务 D 基于 origin/main 重做后新开 PR(分支 oac-4/node-endpoint 保留参考)。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant