diff --git a/deploy/bootstrap.sh b/deploy/bootstrap.sh index e3faaf2..9f05fbf 100644 --- a/deploy/bootstrap.sh +++ b/deploy/bootstrap.sh @@ -437,10 +437,23 @@ validate_nodeport() { fi } +# A value without a usable port would reach the firewall and the summary as-is: 8081 opens +# port 8081 while nano binds nothing, 127.0.0.1 prints http://127.0.0.1:127.0.0.1/..., and +# the unit crash-loops either way. +validate_listen() { + local name="$1" value="$2" port="${2##*:}" + case "$value" in *:*) ;; *) port="" ;; esac + case "$port" in + ''|*[!0-9]*) die "${name} must be host:port (for example 127.0.0.1:8081), got: ${value}" ;; + esac + [ "$port" -ge 1 ] && [ "$port" -le 65535 ] || die "${name} port must be 1-65535, got: ${value}" +} + validate_settings() { validate_timeout PKG_LOCK_TIMEOUT "$PKG_LOCK_TIMEOUT" validate_timeout APT_LOCK_TIMEOUT "$APT_LOCK_TIMEOUT" validate_nodeport FELIS_PANEL_NODEPORT "$FELIS_PANEL_NODEPORT" + validate_listen FELIS_NANO_LISTEN "$FELIS_NANO_LISTEN" } # --------------------------------------------------------------------------- diff --git a/deploy/bootstrap_test.sh b/deploy/bootstrap_test.sh index ac000e7..114e55a 100644 --- a/deploy/bootstrap_test.sh +++ b/deploy/bootstrap_test.sh @@ -276,6 +276,25 @@ expect "a first install listens on loopback" "LISTEN: 127.0.0.1:8081" \ expect "a first install takes the operator's address" "LISTEN: 10.0.0.5:8081" \ "$(run_listen 10.0.0.5:8081 "$sdir/absent.service")" +# Whatever the address came from, it reaches the firewall, the summary and the unit as-is. +lblock="$(awk '/^validate_listen\(\) \{/,/^}/' "$BS")" +[ -n "$lblock" ] || { echo "FAIL: no validate_listen found in $BS"; exit 1; } +[ "$(printf '%s\n' "$lblock" | wc -l)" -lt 20 ] \ + || { echo "FAIL: the extracted block is not the function -- did its closing brace move?"; exit 1; } + +check_listen() { # value + bash -c 'die() { printf "DIE: %s\n" "$*"; exit 1; } + '"$lblock"' + validate_listen FELIS_NANO_LISTEN "$1" && echo VALID' _ "$1" 2>&1 +} + +for v in 8081 127.0.0.1 127.0.0.1:0 127.0.0.1:65536 127.0.0.1:x; do + expect "listen address $v is refused" "DIE: FELIS_NANO_LISTEN" "$(check_listen "$v")" +done +for v in '[::1]:8081' 0.0.0.0:8081 127.0.0.1:8081; do + expect "listen address $v is accepted" VALID "$(check_listen "$v")" +done + pblock="$(awk '/^prompt_install_mode\(\) \{/,/^}/' "$BS")" [ -n "$pblock" ] || { echo "FAIL: no prompt_install_mode found in $BS"; exit 1; } [ "$(printf '%s\n' "$pblock" | wc -l)" -lt 60 ] \