Repository navigation
fix(fleet): complete the enroll port/auth layout + pin real version + sign the build (#1354) - #1357
Conversation
… sign the build (#1354) Follow-up to #1355. Bringing a real server up surfaced that the port picture was incomplete, plus two more enrollment blockers. Ports — the -1 offset from #1355 put the extension's app shelf (configuredPort + 1) right back on FLEET_PORT, colliding with the hub service; and the hub's own embedded engine defaulted to the same port as the extension engine. Final server layout, no overlap: FLEET_PORT-3 hub-engine · FLEET_PORT-2 ext-engine · FLEET_PORT-1 app-shelf · FLEET_PORT hub-service - install.sh: server want_port = FLEET_PORT-2; hub plist/unit set AMICODE_ENGINE_PORT=FLEET_PORT-3. Auth — AMICODE_SERVICE_AUTH=open only bypasses the SERVICE's auth; /global/health proxies to the engine, which 401s if it holds a password (verify-attach reads that 401 as auth-rejected). The hub engine now runs AMICODE_ENGINE_UNARMED=1 — open-auth's matched pair. The SSH tunnel is the boundary. Pin version — enroll --as-server defaulted pin_version to "dev", which fails the enroll-time pin-check against the server's own 1.18.x engine before verify-attach runs. It now probes the just-provisioned local hub's /global/health and pins the REAL version; AMICO_CLIENT_VERSION / an injected clientVersion still override; "dev" survives only as the unreachable-at-mint fallback. Codesign — build_binary.mjs (the CLI build path) never signed the compiled binary; on macOS Gatekeeper silently kills an unsigned/modified Mach-O on spawn (exit, no output), so every build:binary produced a binary that could not run until hand-signed. It now ad-hoc-signs on darwin (codesign --sign - --force) and hashes the on-disk file post-sign so .sha256 matches what ships. The TS hub-service renderer (fleet_hub_service.ts) is not wired to production, but #1355 had already set AMICODE_SERVICE_AUTH=open there — a broken posture without the unarmed engine + non-colliding port. Kept it consistent so it is not a latent landmine. Tests: +3 pin-version cases (probe / fallback / env-override), +3 hub-service env cases (engine-port / unarmed / corrected port convention), projection test updated to the -2 offset and asserts the shell-rendered unit carries AMICODE_ENGINE_PORT + AMICODE_ENGINE_UNARMED. Full amico-run suite (1740) green; fleet extension suites green; both install.sh copies byte-identical.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Follow-up findings from this session filed as separate issues (not blockers for this PR):
|
… sign the build (#1354) (#1357) Follow-up to #1355. Bringing a real server up surfaced that the port picture was incomplete, plus two more enrollment blockers. Ports — the -1 offset from #1355 put the extension's app shelf (configuredPort + 1) right back on FLEET_PORT, colliding with the hub service; and the hub's own embedded engine defaulted to the same port as the extension engine. Final server layout, no overlap: FLEET_PORT-3 hub-engine · FLEET_PORT-2 ext-engine · FLEET_PORT-1 app-shelf · FLEET_PORT hub-service - install.sh: server want_port = FLEET_PORT-2; hub plist/unit set AMICODE_ENGINE_PORT=FLEET_PORT-3. Auth — AMICODE_SERVICE_AUTH=open only bypasses the SERVICE's auth; /global/health proxies to the engine, which 401s if it holds a password (verify-attach reads that 401 as auth-rejected). The hub engine now runs AMICODE_ENGINE_UNARMED=1 — open-auth's matched pair. The SSH tunnel is the boundary. Pin version — enroll --as-server defaulted pin_version to "dev", which fails the enroll-time pin-check against the server's own 1.18.x engine before verify-attach runs. It now probes the just-provisioned local hub's /global/health and pins the REAL version; AMICO_CLIENT_VERSION / an injected clientVersion still override; "dev" survives only as the unreachable-at-mint fallback. Codesign — build_binary.mjs (the CLI build path) never signed the compiled binary; on macOS Gatekeeper silently kills an unsigned/modified Mach-O on spawn (exit, no output), so every build:binary produced a binary that could not run until hand-signed. It now ad-hoc-signs on darwin (codesign --sign - --force) and hashes the on-disk file post-sign so .sha256 matches what ships. The TS hub-service renderer (fleet_hub_service.ts) is not wired to production, but #1355 had already set AMICODE_SERVICE_AUTH=open there — a broken posture without the unarmed engine + non-colliding port. Kept it consistent so it is not a latent landmine. Tests: +3 pin-version cases (probe / fallback / env-override), +3 hub-service env cases (engine-port / unarmed / corrected port convention), projection test updated to the -2 offset and asserts the shell-rendered unit carries AMICODE_ENGINE_PORT + AMICODE_ENGINE_UNARMED. Full amico-run suite (1740) green; fleet extension suites green; both install.sh copies byte-identical.
Follow-up to #1355 — the rest of the fleet-enroll story
Bringing a real Mac Studio server up (and enrolling a MacBook Pro against it end-to-end) surfaced that #1355 fixed the right class of bugs but the port picture was incomplete, plus two more enrollment blockers and a build-time footgun.
The corrected server port layout (no collisions)
FLEET_PORT-3AMICODE_ENGINE_PORT)FLEET_PORT-2amicode.opencodePort)FLEET_PORT-1configuredPort + 1)FLEET_PORTWhat was wrong
-1offset put the extension's app shelf (configuredPort + 1) right back onFLEET_PORT, colliding with the hub service. Fixed with a-2offset so the app shelf lands onFLEET_PORT-1.FLEET_PORT-3viaAMICODE_ENGINE_PORT.AMICODE_SERVICE_AUTH=openonly bypasses the service's auth;/global/healthproxies to the engine, which401s if it holds a password — andverify-attachreads that401asauth-rejected. The hub engine now runsAMICODE_ENGINE_UNARMED=1, open-auth's matched pair. The SSH tunnel is the boundary.enroll --as-serverdefaultedpin_versionto"dev", which fails the enroll-time pin-check against the server's own1.18.xengine before verify-attach runs. It now probes the just-provisioned local hub's/global/healthand pins the real version;AMICO_CLIENT_VERSION/ an injectedclientVersionstill override;"dev"survives only as the unreachable-at-mint fallback.build_binary.mjs(the CLI build path) never signed the compiled binary. On macOS, Gatekeeper silently kills an unsigned/modified Mach-O on spawn (exit, no output), so everybuild:binaryproduced a binary that couldn't run until hand-signed. It now ad-hoc-signs on darwin (codesign --sign - --force) and hashes the on-disk file post-sign so.sha256matches what ships. Verified:codesign -vreports a valid signature and the binary runs standalone.Consistency note
The TS hub-service renderer (
fleet_hub_service.ts) isn't wired to production, but #1355 had already setAMICODE_SERVICE_AUTH=openthere — a broken posture without the unarmed engine + non-colliding port. Kept it consistent so it isn't a latent landmine if anyone wires it in.Verification
verify_attach: {ok: true}, roster shows the laptopreachable,/global/health200through the tunnel.-2offset and now asserts the shell-rendered unit carriesAMICODE_ENGINE_PORT+AMICODE_ENGINE_UNARMED. Fullamico-runsuite 1740 green; fleet extension suites green; bothinstall.shcopies byte-identical; extension typecheck clean.Not in this PR (filed separately)
defaultRunInstalleronly resolvesAMICO_FLEET_INSTALLERor the dev-checkout path — nothing sets the env, so released (non-dev) enrollment's installer step likely can't findinstall.sh.opencode serveprocesses survive reloads and squat on ports (possibly related to the session-restore regression).Closes the enrollment path opened by #1354.