rig/changelog.d
cluade-reviewer-andresmgsl 7f2501d0fe
Some checks failed
ci / check (pull_request) Failing after 7s
ci / install (pull_request) Successful in 4s
ci / db-integration (pull_request) Successful in 4s
labels / labels (pull_request) Failing after 7s
fix: refuse a PATH without /usr/sbin, before the token prompt
Reported from a real ci-box: `rig forgejo-runner install` read a registration
token off the operator's terminal and then died with

  …/forgejo-runner-install.sh: line 250: useradd: command not found

rig checked `id -u` and concluded it could administer the machine. Being root
and being able to FIND the admin binaries are different facts, and only the
first was asserted. `su` without `-`, sudo with a sanitised secure_path, and
several container images all produce a root shell with no /usr/sbin on PATH,
which is where useradd lives.

Three call sites had it: both runner installers and users apply. The last is
the worst — it runs mid-convergence, so a PATH-shorn root could fail partway
through a user sweep rather than before it starts.

require_admin_bins refuses rather than repairing PATH itself: a command that
quietly prepends /usr/sbin teaches the operator nothing and leaves a
misconfigured host misconfigured. The message names the remedy and,
deliberately, not this script — echoing an internal path back at someone who
typed `rig forgejo-runner install` is the unhelpful half of the original error.

It sits beside each root check, so identity and capability are asserted
together and before anything is spent. A secret typed for a run that could
never succeed is the avoidable half of this bug, and there is a test for
exactly that ordering.

Closes #139

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-01 18:39:03 +00:00
..
109.md docs: the changelog fragment cites bare #109 2026-07-28 09:26:17 +00:00
111.md docs: shorten changelog.d/111.md under the 300-char entry guard 2026-07-29 14:45:57 +00:00
112.md docs: the changelog fragment says what changed and stops 2026-07-29 12:22:08 +00:00
116.md fix: preserve triage across both forges 2026-07-30 18:31:16 +00:00
129.md feat(drill): a forgejo-runner lifecycle leg beside the GitHub one 2026-07-30 23:27:36 +00:00
131.md docs: README install quick start names the Forgejo channel (RIG_HOST) 2026-07-30 23:52:44 +00:00
133.md fix(forgejo-runner): 'active' is not proof the runner is fetching 2026-07-31 00:15:02 +00:00
135.md fix(forgejo-runner): the cache server can start 2026-07-31 16:59:03 +00:00
139.md fix: refuse a PATH without /usr/sbin, before the token prompt 2026-08-01 18:39:03 +00:00
152.md fix: group machine role changelog entry 2026-07-25 13:07:01 +00:00
153.md fix: group template snapshot changelog entry 2026-07-25 16:00:29 +00:00
160.md fix: scope the netmap tag read to Self 2026-07-25 16:02:54 +00:00
162.md fix: arm cron on agent tenant boxes 2026-07-25 18:54:27 +00:00
README.md feat: convert unreleased changelog to fragments 2026-07-24 13:55:28 +00:00

changelog.d/ — the next release's section, one fragment per issue

Machine-assembled by bin/changelog-assemble (#112): every PR that changes behavior writes one file here — <issue>.md, the exact prose that will be published, nothing else — and the release PR folds them all into the next ## X.Y.Z — DATE section of CHANGELOG.md, consuming them. Distinct filenames never conflict, which is this directory's whole reason to exist. This README is the marker that keeps the directory tracked when it holds no fragments (#112 D1) — changelog-armed refuses a tree without it; do not delete it.