Files
mesh-catalog/modules/sudo/cmd/sudo-tools/main.go
T
jochen f015aba34a sudo: declare the operator account's passwordless escalation as a module
Three modules' tools act through `sudo -n` and nothing declared that the
account may; each machine said so in a hand-set line in /etc/sudoers. The
module owns the package and /etc/sudoers.d/10-mesh-operator (0440), checked
by visudo in its manifest test, and serves sudo_rules, sudo_check and
sudo_drop_ins from a Go bundle. lab stops declaring the sudo package, which
would collide with this module on the node that runs both (hq ADR 0207,
to-be 42 Phase 1).
2026-10-04 12:50:20 +02:00

57 lines
2.3 KiB
Go

// sudo's tools bundle (novox/hq to-be 42 Phase 1, research 026/05): a process the node's runtime
// launches and speaks MCP over stdio to, through the Go SDK (ADR 0188, ADR 0193). It answers what
// sudo grants the operator account and whether the passwordless escalation every module's acting
// tools rely on works here. It changes nothing: the grant itself is the module's drop-in, which the
// host writes.
package main
import (
"context"
"fmt"
"os"
stdio "git.novox.be/novox/mesh-sdk/go"
)
// binaryName is what the build names this bundle's executable: the manifest's `binary`.
const binaryName = "sudo-tools"
func bg() context.Context { return context.Background() }
func main() {
// An empty name serves as the module the runtime names (MESH_SERVED_MODULE): sudo.
if err := stdio.Serve("", tools(ThisMachine())); err != nil {
fmt.Fprintln(os.Stderr, err)
os.Exit(1)
}
}
func tools(m *Machine) []stdio.Tool {
return []stdio.Tool{
{
Name: "sudo_rules",
Description: "What the runtime's account may run through sudo on this machine, as `sudo -n -l` says it: " +
"the defaults in force and each rule with its run-as, tags (NOPASSWD …) and commands, and whether one " +
"lets it run everything as root without a prompt. An error when sudo itself asks for a password.",
Input: schema(map[string]any{}),
Run: func(map[string]any) (any, error) { return m.ListRules() },
},
{
Name: "sudo_check",
Description: "Does the passwordless escalation the mesh's acting tools rely on work here, and which file grants it: " +
"every rule in /etc/sudoers and its drop-ins naming the operator account, one of its groups or ALL, in " +
"the order sudo reads them, the one that decides, and whether the module's own drop-in is present.",
Input: schema(map[string]any{}),
Run: func(map[string]any) (any, error) { return m.CheckEscalation() },
},
{
Name: "sudo_drop_ins",
Description: "The files of /etc/sudoers.d with owner, mode and size, whether sudo reads each (a name with a dot " +
"or ending in ~, another owner or a group- or world-writable mode is skipped), whether each parses " +
"(visudo -cf), and whether sudo's rules as a whole parse. A file that does not parse locks sudo for everyone.",
Input: schema(map[string]any{}),
Run: func(map[string]any) (any, error) { return m.ListDropIns() },
},
}
}