Name the account agents run as on a node, and say whether it can become root
On the control node every agent ran as the operator's account, which has passwordless sudo, so an agent could become root without a person (hq ADR 0266). A node now names an agent account at the controller's terminal only; the agent's module declares it never to become root, the node-engine judges that, and the self-check (DA) raises agent-can-become-root while it does not hold, so ADR 0259's router can rest on it.
This commit is contained in:
@@ -241,6 +241,31 @@ type Rendering struct {
|
||||
// refuses a field it does not know, whole — so to it the field is not sent, and what it runs is
|
||||
// judged by liveness alone.
|
||||
ReadsHealth bool
|
||||
|
||||
// JudgesRoot says this machine's node-engine judges a user's declared `root` (novox/hq ADR 0266: its
|
||||
// statement's contract is link.RootContract or later). To an older, strict engine the field is not
|
||||
// sent, and the account it names is not judged — which the self-check says, as not judged.
|
||||
JudgesRoot bool
|
||||
}
|
||||
|
||||
// RootField is a user resource's field saying the account must never become root without a person
|
||||
// (novox/hq ADR 0266).
|
||||
const RootField = "root"
|
||||
|
||||
// rootInto composes a user's `root` for the node-engine: taken away when it asserts nothing (empty — a
|
||||
// machine where agents run as the operator) or when the engine is older than the field and parses
|
||||
// strictly; kept as "never" otherwise.
|
||||
func rootInto(resource map[string]any, with Rendering) {
|
||||
if resource["type"] != "user" {
|
||||
return
|
||||
}
|
||||
value, has := resource[RootField]
|
||||
if !has {
|
||||
return
|
||||
}
|
||||
if s, _ := value.(string); s == "" || !with.JudgesRoot {
|
||||
delete(resource, RootField)
|
||||
}
|
||||
}
|
||||
|
||||
// machinePort is where a module's port lives on this machine, or the port itself when the mesh has
|
||||
@@ -981,6 +1006,9 @@ func (r Resolution) compose(with Rendering, owner map[string]string,
|
||||
// How it is ready, in the node-engine's words: its endpoint as the port this machine
|
||||
// published it on — or not sent at all to an engine older than the field (ADR 0240).
|
||||
healthInto(copied, m, with)
|
||||
// And a user's `root` (novox/hq ADR 0266): sent only when it asserts something, to an engine
|
||||
// that judges it.
|
||||
rootInto(copied, with)
|
||||
// The account's environment and every module's shell code, where this module holds the
|
||||
// seat that places them (novox/hq ADR 0203, ADR 0204). Gathered from every module on
|
||||
// the node, as the jails are, and **last of every placeholder pass**: shell code is a
|
||||
|
||||
Reference in New Issue
Block a user