Исправлен rollback/firewall lifecycle и shell execution, синхронизирована документация
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
import type { InstallContext } from "../types/context";
|
||||
import { runVisible } from "../lib/process";
|
||||
import { runRawVisible, runVisible } from "../lib/process";
|
||||
|
||||
async function ensureRuntimeIdentity(user: string, expectedHome: string): Promise<void> {
|
||||
const checkCmd = `
|
||||
@@ -23,7 +23,7 @@ else
|
||||
useradd --system --home ${expectedHome} --shell /usr/sbin/nologin ${user}
|
||||
fi
|
||||
`;
|
||||
await runVisible`${checkCmd}`;
|
||||
await runRawVisible(checkCmd);
|
||||
}
|
||||
|
||||
export async function prepareFilesystem(context: InstallContext): Promise<void> {
|
||||
|
||||
@@ -124,6 +124,11 @@ export async function rollbackFirewallNow(context: RuntimeContext): Promise<void
|
||||
return;
|
||||
}
|
||||
|
||||
if (!(await exists("/etc/nftables.d/nftables.conf.existed")) && !(await exists("/etc/nftables.d/hy2xs.nft.existed"))) {
|
||||
info("firewall rollback skipped: no HY2XS rollback markers found");
|
||||
return;
|
||||
}
|
||||
|
||||
if (context.config.firewallStagedApply) {
|
||||
await runVisible`systemctl stop hy2xs-fw-rollback || true`;
|
||||
await runVisible`systemctl reset-failed hy2xs-fw-rollback || true`;
|
||||
@@ -131,6 +136,6 @@ export async function rollbackFirewallNow(context: RuntimeContext): Promise<void
|
||||
|
||||
await runVisible`if [ -f /etc/nftables.d/nftables.conf.existed ]; then cp -a /etc/nftables.conf.hy2xs.bak /etc/nftables.conf 2>/dev/null || true; else rm -f /etc/nftables.conf; fi`;
|
||||
await runVisible`if [ -f /etc/nftables.d/hy2xs.nft.existed ]; then cp -a /etc/nftables.d/hy2xs.nft.bak /etc/nftables.d/hy2xs.nft 2>/dev/null || true; else rm -f /etc/nftables.d/hy2xs.nft; fi`;
|
||||
await runVisible`nft -f /etc/nftables.conf >/dev/null 2>&1 || true`;
|
||||
await runVisible`if [ -f /etc/nftables.d/nftables.conf.existed ]; then nft -f /etc/nftables.conf >/dev/null 2>&1 || true; else nft flush ruleset >/dev/null 2>&1 || true; fi`;
|
||||
await runVisible`rm -f ${FW_BACKUP_FILES}`;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user