From 7a9fadc21ad994c361219145886ddc62de31e207 Mon Sep 17 00:00:00 2001 From: atlas Date: Sat, 26 Sep 2026 18:05:40 +0200 Subject: [PATCH] host-modules: convert swarm-bao's HSM-PIN env writer to atomic_write_secret MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit swarm-bao-token's pin.env write (the BAO_HSM_PIN EnvironmentFile for openbao's pkcs11 seal) had the same write-then-chmod-on-live-path shape as the sites already converted: printf > path directly on the live file, chmod after. Same fix, same helper. Content ("BAO_HSM_PIN=\n") and final mode (0400, root-owned — no chown, same as before) are unchanged; pin.env stays at the same path, so openbao's EnvironmentFile= reference needs no change. Refs #4723 --- nix/host-modules/swarm-bao.nix | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/nix/host-modules/swarm-bao.nix b/nix/host-modules/swarm-bao.nix index 459934f3..05daa859 100644 --- a/nix/host-modules/swarm-bao.nix +++ b/nix/host-modules/swarm-bao.nix @@ -2595,6 +2595,9 @@ in }; script = '' set -euo pipefail + + ${atomicWriteSecret} + install -d -m 0770 -g ${tokenGroup} ${tokenStoreDir} # Required whenever the store is not at its default location, or the # library cannot find the token the seal asks for. @@ -2644,8 +2647,7 @@ in chgrp ${tokenGroup} ${tokenStoreDir}/tpm2_pkcs11.sqlite3 chmod 0660 ${tokenStoreDir}/tpm2_pkcs11.sqlite3 - ( umask 077; printf 'BAO_HSM_PIN=%s\n' "$(cat ${tokenStoreDir}/user-pin)" > ${pinEnvFile} ) - chmod 0400 ${pinEnvFile} + printf 'BAO_HSM_PIN=%s\n' "$(cat ${tokenStoreDir}/user-pin)" | atomic_write_secret 0400 "" ${pinEnvFile} ''; };