Unverified Commit 17b43964 authored by Minseong Choi's avatar Minseong Choi 💬
Browse files

fix(bootstrap): carry auth_source tables with spaced or quoted headers

A re-run copies the operator's [[auth_source]] tables from the existing
felis toml into the new one. The awk program that finds them matched
only the literal header [[auth_source]], so a table written as
[[ auth_source ]], [["auth_source"]] or [['auth_source']], all valid
TOML, was taken for some other section and dropped from the config.

Each section header now decides afresh whether it opens an auth_source
table, through one regex that allows inner whitespace and a single- or
double-quoted key. The single quote is spelled \047, which gawk and
mawk both honour inside a bracket expression. The harness carries each
spelling and checks that the table still stops at the next section.
parent c2a5645c
Loading
Loading
Loading
Loading
+3 −2
Changes for deploy/bootstrap.sh: 3 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -1947,8 +1947,9 @@ persisted_auth_source_blocks() {
  for f in "${STATE_DIR}/felis.host.toml" "${STATE_DIR}/felis.pod.toml"; do
    [ -r "$f" ] || continue
    # Every [[auth_source]] table, up to (not including) the next other section header.
    awk '/^[[:space:]]*\[\[auth_source\]\]/ { f=1 }
         f && /^[[:space:]]*\[/ && !/^[[:space:]]*\[\[auth_source\]\]/ { f=0 }
    # TOML also accepts [[ auth_source ]] and a quoted key; a header this does not
    # recognise would silently drop that table.
    awk '/^[[:space:]]*\[/ { f = /^[[:space:]]*\[\[[[:space:]]*["\047]?auth_source["\047]?[[:space:]]*\]\]/ }
         f { print }' "$f"
    return 0
  done
+13 −0
Changes for deploy/bootstrap_test.sh: 13 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -179,6 +179,19 @@ out="$(run_carry)"
expect "both encoder-written tables are carried (first)" '  tag = "littleskin"' "$out"
expect "both encoder-written tables are carried (second)" '  tag = "guild"' "$out"

# TOML allows spaces inside the brackets and a quoted key. Each is still the operator's table.
for hdr in '[[ auth_source ]]' '[["auth_source"]]' "[['auth_source']]"; do
  printf '%s\n' "$hdr" 'tag = "guild"' 'prefix = "GD"' 'url = "https://b.example"' '' \
    '[smtp]' 'host = "mail.example"' > "$sdir/felis.host.toml"
  out="$(run_carry)"
  expect "a $hdr header is carried" "$hdr" "$out"
  expect "a $hdr table keeps its keys" 'tag = "guild"' "$out"
  case "$out" in
    *"[smtp]"*) echo "FAIL a $hdr table must stop at the next section:"; echo "$out"; fails=$((fails + 1)) ;;
    *) echo "PASS a $hdr table stops at the next section" ;;
  esac
done

# --- write_nano_config leaves the unit able to read its config ---------------------------
# felis-nano runs as a DynamicUser, so the directory must be searchable by others under a
# hardened umask too -- but an existing one, which the full install locks to 0700 for its