// sudo's tools bundle (novox/hq to-be 42 Phase 1, research 026/05): a process the node's runtime // launches and speaks MCP over stdio to, through the Go SDK (ADR 0188, ADR 0193). It answers what // sudo grants the operator account and whether the passwordless escalation every module's acting // tools rely on works here. It changes nothing: the grant itself is the module's drop-in, which the // host writes. package main import ( "context" "fmt" "os" stdio "git.novox.be/novox/mesh-sdk/go" ) // binaryName is what the build names this bundle's executable: the manifest's `binary`. const binaryName = "sudo-tools" func bg() context.Context { return context.Background() } func main() { // An empty name serves as the module the runtime names (MESH_SERVED_MODULE): sudo. if err := stdio.Serve("", tools(ThisMachine())); err != nil { fmt.Fprintln(os.Stderr, err) os.Exit(1) } } func tools(m *Machine) []stdio.Tool { return []stdio.Tool{ { Name: "sudo_rules", Description: "What the runtime's account may run through sudo on this machine, as `sudo -n -l` says it: " + "the defaults in force and each rule with its run-as, tags (NOPASSWD …) and commands, and whether one " + "lets it run everything as root without a prompt. An error when sudo itself asks for a password.", Input: schema(map[string]any{}), Run: func(map[string]any) (any, error) { return m.ListRules() }, }, { Name: "sudo_check", Description: "Does the passwordless escalation the mesh's acting tools rely on work here, and which file grants it: " + "every rule in /etc/sudoers and its drop-ins naming the operator account, one of its groups or ALL, in " + "the order sudo reads them, the one that decides, and whether the module's own drop-in is present.", Input: schema(map[string]any{}), Run: func(map[string]any) (any, error) { return m.CheckEscalation() }, }, { Name: "sudo_drop_ins", Description: "The files of /etc/sudoers.d with owner, mode and size, whether sudo reads each (a name with a dot " + "or ending in ~, another owner or a group- or world-writable mode is skipped), whether each parses " + "(visudo -cf), and whether sudo's rules as a whole parse. A file that does not parse locks sudo for everyone.", Input: schema(map[string]any{}), Run: func(map[string]any) (any, error) { return m.ListDropIns() }, }, } }