Count the quiet after a restart from when the controller first saw the search pending
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery failed: its walk failed: a gate on a first machine (what it carried put back), a build, a machine
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery failed: its walk failed: a gate on a first machine (what it carried put back), a build, a machine
The node-engine's own since starts again at every restart, so an agent that restarted the engine in a loop kept agent-can-become-root quiet for ever (the review of 2026-10-09). The controller now keeps when it first saw the verdict waiting for the setuid search (migration 0085), forgets it at the next complete verdict, and raises once the engine's own bound has passed since; the bound and the pending reason are read from mesh-host's rootsearch.
This commit is contained in:
@@ -8,6 +8,7 @@ package link
|
||||
|
||||
import (
|
||||
"encoding/base64"
|
||||
"github.com/novox/mesh-host/rootsearch"
|
||||
"strconv"
|
||||
"strings"
|
||||
"time"
|
||||
@@ -431,14 +432,13 @@ const RootContract = 3
|
||||
const ReasonRoot = "can become root without a person"
|
||||
|
||||
// ReasonRootPending starts the reason of an account verdict the node-engine cannot give yet because its search
|
||||
// for setuid programs, started when the engine started, has not finished (mesh-host internal/accounts
|
||||
// ReasonPending): not judged yet, said as such, never a pass. The search is bounded (RootSearchBound); one that
|
||||
// fails or runs out its bound is said in other words, as not judged (search incomplete).
|
||||
const ReasonRootPending = "not judged yet (search running)"
|
||||
// for setuid programs, started when the engine started, has not finished: not judged yet, said as such, never a
|
||||
// pass. The node-engine's own words (mesh-host rootsearch.ReasonPending), read from it rather than copied.
|
||||
const ReasonRootPending = rootsearch.ReasonPending
|
||||
|
||||
// RootSearchBound is the longest the node-engine lets one search for setuid programs run (mesh-host
|
||||
// internal/accounts SearchBound).
|
||||
const RootSearchBound = 15 * time.Minute
|
||||
// rootsearch.Bound): the one value both read.
|
||||
const RootSearchBound = rootsearch.Bound
|
||||
|
||||
// RootNever is the value of a user's `root`, and of a verdict's Root, that the account must never become
|
||||
// root without a person (ADR 0266).
|
||||
|
||||
Reference in New Issue
Block a user