sudo: declare the operator account's passwordless escalation as a module
Three modules' tools act through `sudo -n` and nothing declared that the account may; each machine said so in a hand-set line in /etc/sudoers. The module owns the package and /etc/sudoers.d/10-mesh-operator (0440), checked by visudo in its manifest test, and serves sudo_rules, sudo_check and sudo_drop_ins from a Go bundle. lab stops declaring the sudo package, which would collide with this module on the node that runs both (hq ADR 0207, to-be 42 Phase 1).
This commit is contained in:
@@ -0,0 +1,56 @@
|
||||
// sudo's tools bundle (novox/hq to-be 42 Phase 1, research 026/05): a process the node's runtime
|
||||
// launches and speaks MCP over stdio to, through the Go SDK (ADR 0188, ADR 0193). It answers what
|
||||
// sudo grants the operator account and whether the passwordless escalation every module's acting
|
||||
// tools rely on works here. It changes nothing: the grant itself is the module's drop-in, which the
|
||||
// host writes.
|
||||
package main
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"os"
|
||||
|
||||
stdio "git.novox.be/novox/mesh-sdk/go"
|
||||
)
|
||||
|
||||
// binaryName is what the build names this bundle's executable: the manifest's `binary`.
|
||||
const binaryName = "sudo-tools"
|
||||
|
||||
func bg() context.Context { return context.Background() }
|
||||
|
||||
func main() {
|
||||
// An empty name serves as the module the runtime names (MESH_SERVED_MODULE): sudo.
|
||||
if err := stdio.Serve("", tools(ThisMachine())); err != nil {
|
||||
fmt.Fprintln(os.Stderr, err)
|
||||
os.Exit(1)
|
||||
}
|
||||
}
|
||||
|
||||
func tools(m *Machine) []stdio.Tool {
|
||||
return []stdio.Tool{
|
||||
{
|
||||
Name: "sudo_rules",
|
||||
Description: "What the runtime's account may run through sudo on this machine, as `sudo -n -l` says it: " +
|
||||
"the defaults in force and each rule with its run-as, tags (NOPASSWD …) and commands, and whether one " +
|
||||
"lets it run everything as root without a prompt. An error when sudo itself asks for a password.",
|
||||
Input: schema(map[string]any{}),
|
||||
Run: func(map[string]any) (any, error) { return m.ListRules() },
|
||||
},
|
||||
{
|
||||
Name: "sudo_check",
|
||||
Description: "Does the passwordless escalation the mesh's acting tools rely on work here, and which file grants it: " +
|
||||
"every rule in /etc/sudoers and its drop-ins naming the operator account, one of its groups or ALL, in " +
|
||||
"the order sudo reads them, the one that decides, and whether the module's own drop-in is present.",
|
||||
Input: schema(map[string]any{}),
|
||||
Run: func(map[string]any) (any, error) { return m.CheckEscalation() },
|
||||
},
|
||||
{
|
||||
Name: "sudo_drop_ins",
|
||||
Description: "The files of /etc/sudoers.d with owner, mode and size, whether sudo reads each (a name with a dot " +
|
||||
"or ending in ~, another owner or a group- or world-writable mode is skipped), whether each parses " +
|
||||
"(visudo -cf), and whether sudo's rules as a whole parse. A file that does not parse locks sudo for everyone.",
|
||||
Input: schema(map[string]any{}),
|
||||
Run: func(map[string]any) (any, error) { return m.ListDropIns() },
|
||||
},
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user