rig/commands
cluade-reviewer-andresmgsl 7aed6ea098
Some checks failed
ci / check (pull_request) Successful in 55s
ci / install (pull_request) Successful in 3s
ci / db-integration (pull_request) Successful in 3s
labels / labels (pull_request) Failing after 7s
fix: preflight every admin binary a command uses, not only useradd
Addresses codex (1538) and kimi (1539): the sweep caught the reported
incident and not the class. Both are right, and there were four sites, not
three.

  forgejo-runner-install  useradd -> useradd usermod   (usermod -aG docker,
                          reached only after the token has been spent)
  users-apply             useradd usermod -> + groupadd (called two lines
                          into convergence), and visudo when a role needs it
  bootstrap-tenant        NEW site (kimi) — usermod -aG docker runs AFTER
                          docker and node are installed, so an unguarded
                          PATH fails it mid-convergence on a changed machine
  runner-install          unchanged: useradd is the only admin binary it
                          calls, and declaring more would refuse boxes that
                          are fine

visudo is checked after the sudo-install block rather than beside the root
check, because until sudo is installed its absence has an innocent cause.
Below that block it does not: sudo is present, so a missing visudo means
/usr/sbin is off PATH. That case is the quiet one — the sudoers block reads
`command -v visudo` as "no sudo on the box means no role needed it", so
apply reported success having granted roles without the escalation those
roles exist for. The other three sites at least crash.

Measured which binaries this covers (Debian 13): useradd, usermod, groupadd,
userdel, groupdel and visudo are /usr/sbin; gpasswd is /usr/bin and so is
NOT affected and deliberately not preflighted. visudo shares the directory
but ships in `sudo`, not `passwd` — which is why it needs its own treatment.

Tests: the sbin-less fixtures could only ever prove the FIRST binary is
named, since useradd wins every race. Six new checks use partial PATHs that
resolve the earlier binaries and withhold exactly one, plus the ordering
assertions (no token prompt, no group created) and the negative case — a
users file needing no sudo must NOT be refused for a missing visudo.

Refs #139
2026-08-02 00:05:02 +00:00
..
lib fix: preflight every admin binary a command uses, not only useradd 2026-08-02 00:05:02 +00:00
bootstrap-tenant.sh fix: preflight every admin binary a command uses, not only useradd 2026-08-02 00:05:02 +00:00
bootstrap-undo.sh feat: Forgejo-native CI — a ci-box tenant and a forgejo-runner family 2026-07-27 20:40:54 +00:00
bootstrap.sh fix: emit BOX_MANUAL line-by-line; bare command for single candidate 2026-07-29 22:38:32 +00:00
coolify-backup-install.sh fix: release channel is tag-only; revert coolify Documentation= 2026-07-29 14:45:40 +00:00
coolify-install.sh feat(bootstrap)!: machine roles carry a -server suffix; staging-server restored 2026-07-20 00:36:00 +00:00
db.sh feat(db): bring ad-hoc dump/restore on-box as rig db 2026-07-17 15:16:35 +00:00
forgejo-runner-install.sh fix: preflight every admin binary a command uses, not only useradd 2026-08-02 00:05:02 +00:00
forgejo-runner-remove.sh fix: one checksum policy, labeler coverage, orphaned-unit removal 2026-07-27 21:19:33 +00:00
forgejo-runner-status.sh test(forgejo-runner): drive the liveness note's state boundary 2026-07-31 20:13:23 +00:00
manifest.sh feat: /etc/rig/manifest — which rig converged this machine, and when 2026-07-20 12:48:39 +00:00
platform.sh feat(platform): ID names the machine — a namespaced sha256 of /etc/machine-id, computed at run time, stored nowhere (#95) 2026-07-24 07:48:45 +00:00
runner-install.sh fix: refuse a PATH without /usr/sbin, before the token prompt 2026-08-01 18:39:03 +00:00
runner-remove.sh fix: headless credential prompts refuse loudly, naming their variable (#42) 2026-07-19 12:15:08 +00:00
runner-repoint.sh fix: headless credential prompts refuse loudly, naming their variable (#42) 2026-07-19 12:15:08 +00:00
runner-status.sh fix(runner): install refuses a box registered to another repo 2026-07-13 14:57:28 +00:00
template-lint.sh test: cover machine template registry 2026-07-25 11:00:21 +00:00
users-apply.sh fix: preflight every admin binary a command uses, not only useradd 2026-08-02 00:05:02 +00:00
users-close-root.sh fix: don't read a missing /run/sshd as a broken sshd config 2026-07-20 17:58:10 +00:00
users-status.sh fix(users): review findings — invoker gate, real SSH revocation, StrictModes-shaped close-root gate, trait-aware box role 2026-07-17 20:01:19 +00:00