Skip to content

feat(setup): the administrator's whr setup initializes workharbor - #529

Merged
wstein merged 2 commits into
mainfrom
feat/setup-host-initializes-account
Oct 9, 2026
Merged

wstein merged 2 commits into
mainfrom
feat/setup-host-initializes-account

Conversation

@wstein

@wstein wstein commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Werner's decision of 2026-10-09 (alpha.5): the administrator's plain whr setup (no host word; whr setup host stays a hidden alias) also initializes the non-admin workharbor account's base configuration, so no whr setup as workharbor is needed for the base state.

  • Phase by who runs it (autoPhase); config-first writes the account's config.json (0600, owner workharbor, never overwritten) and /etc/whr/config.json (only when missing).
  • No root write inside the account's home: folders via sudo -u workharbor /bin/mkdir -p -m 0700, file staged in root-owned /etc/whr and copied with sudo -u workharbor /bin/cp -n; symlink/owner guard as defence in depth.
  • Steps that need workharbor's own desktop session (container start, API token, agent key, ssh-ca, GitHub App, tool store, service install, drop-admin) stay with the account's run.
  • Manual pages, doctor wording, hints and goldens updated; alpha.4 upgrade path via --config.

Opus review (security-relevant): NOT CLEAR at 6427563e (1 High: root install -d -o followed a symlink in the account's home, 3 Medium, 5 Low), all fixed; CLEAR at 29da874 (11 mutations caught). Unverified on a real host: sudo -u workharbor mkdir/cp -n, visibility into /Users/workharbor (clean-Mac run).

Design pages (D46, D49, D59, homebrew-bootstrap, interfaces) follow in a separate design PR (D61).

Refs #510 (the roots of the administrator run now come from the system config this change writes; whether #510 can close is for the human to decide)

🤖 Generated with Claude Code

wstein and others added 2 commits October 9, 2026 14:24
The administrator's run writes the account's base config (0600, owned by
the account, never overwritten) and, when missing, the system config.
Root never writes inside the account's home: folders and file are made
as the account with sudo -u, the file staged under root-owned /etc/whr.
whr setup picks the administrator or the account part by who runs it;
`whr setup host` stays as a hidden alias.

Refs: #471
Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
Drop the `setup host` commands, describe config-first for a separate
account and its residual risks, name what stays for the workharbor
desktop session, and note the alias in the upgrade section.

Refs: #471
Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
@wstein

wstein commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

Opus security review: NOT CLEAR at 6427563e (1 High: root install -d -o followed a symlink in the account's home; 3 Medium; 5 Low), all fixed; CLEAR at 29da874 after 11 mutations were caught; reviewer ran go test ./..., make check-ci and make commitlint (exit 0). Unverified on a real host: sudo -u workharbor mkdir/cp -n, visibility into /Users/workharbor (clean-Mac run). Open Lows: late rechecks untested, host-setup.md:15 wording of the unverified install arguments, a stage file left in /etc/whr when cp fails.

Co-Authored-By: Claude Sonnet 5.5 [email protected]

@wstein
wstein marked this pull request as ready for review October 9, 2026 12:37
@wstein
wstein merged commit 0d65b8a into main Oct 9, 2026
20 of 22 checks passed
@wstein
wstein deleted the feat/setup-host-initializes-account branch October 9, 2026 12:44
wstein added a commit that referenced this pull request Oct 9, 2026
The entry on the administrator's workspace roots now describes what
#529 built: config-first's check, fix text and commands as the code
words them, the recheck before the commands, the system-config
fallback for the roots steps, and what stays unverified until the
clean-Mac run.

Refs: #399
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant