Tests that read ../../../mesh-catalog or ../../../mesh-host gave a verdict that depended on what sat beside the checkout: a stale or dirty sibling failed them on a desktop, and a missing one skipped them unseen. They now read the clone the build seat puts in MESH_CHECK_BESIDE, failing when it is absent there, and elsewhere a copy captured at a named commit. The skip had hidden that the builder test read a module retired by ADR 0190. The systemd reading test no longer counts the machine's own environment.d.
43 lines
1.4 KiB
Plaintext
43 lines
1.4 KiB
Plaintext
{
|
|
"module": "sudo",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"package-manager"
|
|
],
|
|
"tools": [
|
|
"sudo_rules",
|
|
"sudo_check",
|
|
"sudo_escalation",
|
|
"sudo_drop_ins"
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "package",
|
|
"type": "package",
|
|
"package": "sudo"
|
|
},
|
|
{
|
|
"id": "operator",
|
|
"type": "file",
|
|
"path": "/etc/sudoers.d/10-mesh-operator",
|
|
"mode": "0440",
|
|
"content": "# The mesh's (module sudo, novox/hq to-be 42, research 027): the operator account escalates\n# without a prompt. The mesh's tools that act as root run `sudo -n` as this account and rely on it;\n# until this file, every machine said so only in a line set by hand in /etc/sudoers.\n# Written whole at every push: an edit here is overwritten. A file of this directory whose name\n# holds a dot or ends in ~ is not read by sudo; this name holds neither.\n# Every command run through sudo gets a terminal of its own (novox/hq ADR 0266): an agent the operator\n# starts as the agent account through sudo cannot push keystrokes into the operator's shell (TIOCSTI).\nDefaults use_pty\n${machine:account} ALL=(ALL:ALL) NOPASSWD: ALL\n"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "tools",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/sudo-tools",
|
|
"binary": "sudo-tools",
|
|
"loads": [
|
|
"sudo-tools"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|