Three modules' tools act through `sudo -n` and nothing declared that the account may; each machine said so in a hand-set line in /etc/sudoers. The module owns the package and /etc/sudoers.d/10-mesh-operator (0440), checked by visudo in its manifest test, and serves sudo_rules, sudo_check and sudo_drop_ins from a Go bundle. lab stops declaring the sudo package, which would collide with this module on the node that runs both (hq ADR 0207, to-be 42 Phase 1).
57 lines
2.3 KiB
Go
57 lines
2.3 KiB
Go
// sudo's tools bundle (novox/hq to-be 42 Phase 1, research 026/05): a process the node's runtime
|
|
// launches and speaks MCP over stdio to, through the Go SDK (ADR 0188, ADR 0193). It answers what
|
|
// sudo grants the operator account and whether the passwordless escalation every module's acting
|
|
// tools rely on works here. It changes nothing: the grant itself is the module's drop-in, which the
|
|
// host writes.
|
|
package main
|
|
|
|
import (
|
|
"context"
|
|
"fmt"
|
|
"os"
|
|
|
|
stdio "git.novox.be/novox/mesh-sdk/go"
|
|
)
|
|
|
|
// binaryName is what the build names this bundle's executable: the manifest's `binary`.
|
|
const binaryName = "sudo-tools"
|
|
|
|
func bg() context.Context { return context.Background() }
|
|
|
|
func main() {
|
|
// An empty name serves as the module the runtime names (MESH_SERVED_MODULE): sudo.
|
|
if err := stdio.Serve("", tools(ThisMachine())); err != nil {
|
|
fmt.Fprintln(os.Stderr, err)
|
|
os.Exit(1)
|
|
}
|
|
}
|
|
|
|
func tools(m *Machine) []stdio.Tool {
|
|
return []stdio.Tool{
|
|
{
|
|
Name: "sudo_rules",
|
|
Description: "What the runtime's account may run through sudo on this machine, as `sudo -n -l` says it: " +
|
|
"the defaults in force and each rule with its run-as, tags (NOPASSWD …) and commands, and whether one " +
|
|
"lets it run everything as root without a prompt. An error when sudo itself asks for a password.",
|
|
Input: schema(map[string]any{}),
|
|
Run: func(map[string]any) (any, error) { return m.ListRules() },
|
|
},
|
|
{
|
|
Name: "sudo_check",
|
|
Description: "Does the passwordless escalation the mesh's acting tools rely on work here, and which file grants it: " +
|
|
"every rule in /etc/sudoers and its drop-ins naming the operator account, one of its groups or ALL, in " +
|
|
"the order sudo reads them, the one that decides, and whether the module's own drop-in is present.",
|
|
Input: schema(map[string]any{}),
|
|
Run: func(map[string]any) (any, error) { return m.CheckEscalation() },
|
|
},
|
|
{
|
|
Name: "sudo_drop_ins",
|
|
Description: "The files of /etc/sudoers.d with owner, mode and size, whether sudo reads each (a name with a dot " +
|
|
"or ending in ~, another owner or a group- or world-writable mode is skipped), whether each parses " +
|
|
"(visudo -cf), and whether sudo's rules as a whole parse. A file that does not parse locks sudo for everyone.",
|
|
Input: schema(map[string]any{}),
|
|
Run: func(map[string]any) (any, error) { return m.ListDropIns() },
|
|
},
|
|
}
|
|
}
|