Loading cmd/felis/node_control.go +2 −2 Changes for cmd/felis/node_control.go: 2 added lines, 2 removed lines. Original line number Diff line number Diff line Loading @@ -172,7 +172,7 @@ func (e nodeExecutor) run(ctx context.Context, r nodecontrol.Request, stage func return err } if len(deployment.Spec.Template.Spec.Containers) == 0 { return errors.New("Felis API image is unavailable") return errors.New("the Felis API image is unavailable") } image := deployment.Spec.Template.Spec.Containers[0].Image if r.Action == "enable" { Loading Loading @@ -301,7 +301,7 @@ func (e nodeExecutor) requireStopped(ctx context.Context, r nodecontrol.Request) continue } if p.Status.Phase != corev1.PodSucceeded && p.Status.Phase != corev1.PodFailed { return fmt.Errorf("Pod %s has not exited (phase %s); wait for game and maintenance workloads to stop", p.Name, p.Status.Phase) return fmt.Errorf("pod %s has not exited (phase %s); wait for game and maintenance workloads to stop", p.Name, p.Status.Phase) } } // Prevent a pending wake intent racing admission or an installation. Loading deploy/bootstrap.sh +3 −2 Changes for deploy/bootstrap.sh: 3 added lines, 2 removed lines. Original line number Diff line number Diff line Loading @@ -5238,8 +5238,9 @@ EOF_NODE_SELINUX d /run/felis-node-control 0750 root 65532 - EOF_NODE_TMP if [ -n "$selinux_environment" ] && command -v semanage >/dev/null 2>&1; then semanage fcontext -a -t felis_node_control_socket_t '/run/felis-node-control(/.*)?' 2>/dev/null \ || semanage fcontext -m -t felis_node_control_socket_t '/run/felis-node-control(/.*)?' # /run is an SELinux equivalence alias for /var/run. Register the canonical path. semanage fcontext -a -t felis_node_control_socket_t '/var/run/felis-node-control(/.*)?' 2>/dev/null \ || semanage fcontext -m -t felis_node_control_socket_t '/var/run/felis-node-control(/.*)?' fi if [ -n "$selinux_environment" ] && command -v chcon >/dev/null 2>&1; then chcon -R -t felis_node_control_socket_t /run/felis-node-control 2>/dev/null || true Loading deploy/bootstrap_test.sh +22 −0 Changes for deploy/bootstrap_test.sh: 22 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -5316,6 +5316,28 @@ out="$(WORKER_TOKEN_FILE="$badtoken" bash -c ' expect "worker refuses a copied server token before changing the machine" 'worker accepts only CA-pinned bootstrap tokens' "$out" rm -f "$badtoken" # SELinux rejects /run paths when the policy aliases them to /var/run. node_fcontext="$(bsfn install_node_control_service | awk '/^ if .*command -v semanage/,/^ fi/')" [ -n "$node_fcontext" ] && [ "$(printf '%s\n' "$node_fcontext" | wc -l)" -lt 12 ] \ || { echo "FAIL: node-control fcontext block could not be extracted"; exit 1; } for existing in 0 1; do out="$(EXISTING="$existing" bash -c ' selinux_environment=enabled semanage() { case "$5" in /run/felis-node-control*) echo "alias conflict"; return 1;; esac echo "$*" [ "$EXISTING" != 1 ] || [ "$2" = -m ] } '"$node_fcontext" )" expect "node-control registers the canonical SELinux path ($existing)" \ "fcontext -a -t felis_node_control_socket_t /var/run/felis-node-control(/.*)?" "$out" if [ "$existing" = 1 ]; then expect "node-control updates an existing canonical rule" \ "fcontext -m -t felis_node_control_socket_t /var/run/felis-node-control(/.*)?" "$out" fi done # --------------------------------------------------------------------------------------- if [ "$fails" -eq 0 ]; then echo "ALL PASS" Loading Loading
cmd/felis/node_control.go +2 −2 Changes for cmd/felis/node_control.go: 2 added lines, 2 removed lines. Original line number Diff line number Diff line Loading @@ -172,7 +172,7 @@ func (e nodeExecutor) run(ctx context.Context, r nodecontrol.Request, stage func return err } if len(deployment.Spec.Template.Spec.Containers) == 0 { return errors.New("Felis API image is unavailable") return errors.New("the Felis API image is unavailable") } image := deployment.Spec.Template.Spec.Containers[0].Image if r.Action == "enable" { Loading Loading @@ -301,7 +301,7 @@ func (e nodeExecutor) requireStopped(ctx context.Context, r nodecontrol.Request) continue } if p.Status.Phase != corev1.PodSucceeded && p.Status.Phase != corev1.PodFailed { return fmt.Errorf("Pod %s has not exited (phase %s); wait for game and maintenance workloads to stop", p.Name, p.Status.Phase) return fmt.Errorf("pod %s has not exited (phase %s); wait for game and maintenance workloads to stop", p.Name, p.Status.Phase) } } // Prevent a pending wake intent racing admission or an installation. Loading
deploy/bootstrap.sh +3 −2 Changes for deploy/bootstrap.sh: 3 added lines, 2 removed lines. Original line number Diff line number Diff line Loading @@ -5238,8 +5238,9 @@ EOF_NODE_SELINUX d /run/felis-node-control 0750 root 65532 - EOF_NODE_TMP if [ -n "$selinux_environment" ] && command -v semanage >/dev/null 2>&1; then semanage fcontext -a -t felis_node_control_socket_t '/run/felis-node-control(/.*)?' 2>/dev/null \ || semanage fcontext -m -t felis_node_control_socket_t '/run/felis-node-control(/.*)?' # /run is an SELinux equivalence alias for /var/run. Register the canonical path. semanage fcontext -a -t felis_node_control_socket_t '/var/run/felis-node-control(/.*)?' 2>/dev/null \ || semanage fcontext -m -t felis_node_control_socket_t '/var/run/felis-node-control(/.*)?' fi if [ -n "$selinux_environment" ] && command -v chcon >/dev/null 2>&1; then chcon -R -t felis_node_control_socket_t /run/felis-node-control 2>/dev/null || true Loading
deploy/bootstrap_test.sh +22 −0 Changes for deploy/bootstrap_test.sh: 22 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -5316,6 +5316,28 @@ out="$(WORKER_TOKEN_FILE="$badtoken" bash -c ' expect "worker refuses a copied server token before changing the machine" 'worker accepts only CA-pinned bootstrap tokens' "$out" rm -f "$badtoken" # SELinux rejects /run paths when the policy aliases them to /var/run. node_fcontext="$(bsfn install_node_control_service | awk '/^ if .*command -v semanage/,/^ fi/')" [ -n "$node_fcontext" ] && [ "$(printf '%s\n' "$node_fcontext" | wc -l)" -lt 12 ] \ || { echo "FAIL: node-control fcontext block could not be extracted"; exit 1; } for existing in 0 1; do out="$(EXISTING="$existing" bash -c ' selinux_environment=enabled semanage() { case "$5" in /run/felis-node-control*) echo "alias conflict"; return 1;; esac echo "$*" [ "$EXISTING" != 1 ] || [ "$2" = -m ] } '"$node_fcontext" )" expect "node-control registers the canonical SELinux path ($existing)" \ "fcontext -a -t felis_node_control_socket_t /var/run/felis-node-control(/.*)?" "$out" if [ "$existing" = 1 ]; then expect "node-control updates an existing canonical rule" \ "fcontext -m -t felis_node_control_socket_t /var/run/felis-node-control(/.*)?" "$out" fi done # --------------------------------------------------------------------------------------- if [ "$fails" -eq 0 ]; then echo "ALL PASS" Loading