fix: register canonical SELinux socket path and pass staticcheck
This commit is contained in:
3 files changed
+27
-4
No files matched your search
@@ -172,7 +172,7 @@ func (e nodeExecutor) run(ctx context.Context, r nodecontrol.Request, stage func
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
if len(deployment.Spec.Template.Spec.Containers) == 0 {
|
if len(deployment.Spec.Template.Spec.Containers) == 0 {
|
||||||
return errors.New("Felis API image is unavailable")
|
return errors.New("the Felis API image is unavailable")
|
||||||
}
|
}
|
||||||
image := deployment.Spec.Template.Spec.Containers[0].Image
|
image := deployment.Spec.Template.Spec.Containers[0].Image
|
||||||
if r.Action == "enable" {
|
if r.Action == "enable" {
|
||||||
@@ -301,7 +301,7 @@ func (e nodeExecutor) requireStopped(ctx context.Context, r nodecontrol.Request)
|
|||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
if p.Status.Phase != corev1.PodSucceeded && p.Status.Phase != corev1.PodFailed {
|
if p.Status.Phase != corev1.PodSucceeded && p.Status.Phase != corev1.PodFailed {
|
||||||
return fmt.Errorf("Pod %s has not exited (phase %s); wait for game and maintenance workloads to stop", p.Name, p.Status.Phase)
|
return fmt.Errorf("pod %s has not exited (phase %s); wait for game and maintenance workloads to stop", p.Name, p.Status.Phase)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
// Prevent a pending wake intent racing admission or an installation.
|
// Prevent a pending wake intent racing admission or an installation.
|
||||||
|
|||||||
+3
-2
@@ -5238,8 +5238,9 @@ EOF_NODE_SELINUX
|
|||||||
d /run/felis-node-control 0750 root 65532 -
|
d /run/felis-node-control 0750 root 65532 -
|
||||||
EOF_NODE_TMP
|
EOF_NODE_TMP
|
||||||
if [ -n "$selinux_environment" ] && command -v semanage >/dev/null 2>&1; then
|
if [ -n "$selinux_environment" ] && command -v semanage >/dev/null 2>&1; then
|
||||||
semanage fcontext -a -t felis_node_control_socket_t '/run/felis-node-control(/.*)?' 2>/dev/null \
|
# /run is an SELinux equivalence alias for /var/run. Register the canonical path.
|
||||||
|| semanage fcontext -m -t felis_node_control_socket_t '/run/felis-node-control(/.*)?'
|
semanage fcontext -a -t felis_node_control_socket_t '/var/run/felis-node-control(/.*)?' 2>/dev/null \
|
||||||
|
|| semanage fcontext -m -t felis_node_control_socket_t '/var/run/felis-node-control(/.*)?'
|
||||||
fi
|
fi
|
||||||
if [ -n "$selinux_environment" ] && command -v chcon >/dev/null 2>&1; then
|
if [ -n "$selinux_environment" ] && command -v chcon >/dev/null 2>&1; then
|
||||||
chcon -R -t felis_node_control_socket_t /run/felis-node-control 2>/dev/null || true
|
chcon -R -t felis_node_control_socket_t /run/felis-node-control 2>/dev/null || true
|
||||||
|
|||||||
@@ -5316,6 +5316,28 @@ out="$(WORKER_TOKEN_FILE="$badtoken" bash -c '
|
|||||||
expect "worker refuses a copied server token before changing the machine" 'worker accepts only CA-pinned bootstrap tokens' "$out"
|
expect "worker refuses a copied server token before changing the machine" 'worker accepts only CA-pinned bootstrap tokens' "$out"
|
||||||
rm -f "$badtoken"
|
rm -f "$badtoken"
|
||||||
|
|
||||||
|
# SELinux rejects /run paths when the policy aliases them to /var/run.
|
||||||
|
node_fcontext="$(bsfn install_node_control_service | awk '/^ if .*command -v semanage/,/^ fi/')"
|
||||||
|
[ -n "$node_fcontext" ] && [ "$(printf '%s\n' "$node_fcontext" | wc -l)" -lt 12 ] \
|
||||||
|
|| { echo "FAIL: node-control fcontext block could not be extracted"; exit 1; }
|
||||||
|
for existing in 0 1; do
|
||||||
|
out="$(EXISTING="$existing" bash -c '
|
||||||
|
selinux_environment=enabled
|
||||||
|
semanage() {
|
||||||
|
case "$5" in /run/felis-node-control*) echo "alias conflict"; return 1;; esac
|
||||||
|
echo "$*"
|
||||||
|
[ "$EXISTING" != 1 ] || [ "$2" = -m ]
|
||||||
|
}
|
||||||
|
'"$node_fcontext"
|
||||||
|
)"
|
||||||
|
expect "node-control registers the canonical SELinux path ($existing)" \
|
||||||
|
"fcontext -a -t felis_node_control_socket_t /var/run/felis-node-control(/.*)?" "$out"
|
||||||
|
if [ "$existing" = 1 ]; then
|
||||||
|
expect "node-control updates an existing canonical rule" \
|
||||||
|
"fcontext -m -t felis_node_control_socket_t /var/run/felis-node-control(/.*)?" "$out"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------------------
|
||||||
if [ "$fails" -eq 0 ]; then
|
if [ "$fails" -eq 0 ]; then
|
||||||
echo "ALL PASS"
|
echo "ALL PASS"
|
||||||
|
|||||||
Reference in new issue
Block a user