host-modules: convert swarm-bao's HSM-PIN env writer to atomic_write_secret

swarm-bao-token's pin.env write (the BAO_HSM_PIN EnvironmentFile for
openbao's pkcs11 seal) had the same write-then-chmod-on-live-path
shape as the sites already converted: printf > path directly on the
live file, chmod after. Same fix, same helper. Content
("BAO_HSM_PIN=<user-pin>\n") and final mode (0400, root-owned — no
chown, same as before) are unchanged; pin.env stays at the same path,
so openbao's EnvironmentFile= reference needs no change.

Refs #4723
This commit is contained in:
atlas 2026-09-26 18:05:40 +02:00 • committed by mara
commit 7a9fadc21a

View file

@ -2595,6 +2595,9 @@ in
};
script = ''
set -euo pipefail
${atomicWriteSecret}
install -d -m 0770 -g ${tokenGroup} ${tokenStoreDir}
# Required whenever the store is not at its default location, or the
# library cannot find the token the seal asks for.
@ -2644,8 +2647,7 @@ in
chgrp ${tokenGroup} ${tokenStoreDir}/tpm2_pkcs11.sqlite3
chmod 0660 ${tokenStoreDir}/tpm2_pkcs11.sqlite3
( umask 077; printf 'BAO_HSM_PIN=%s\n' "$(cat ${tokenStoreDir}/user-pin)" > ${pinEnvFile} )
chmod 0400 ${pinEnvFile}
printf 'BAO_HSM_PIN=%s\n' "$(cat ${tokenStoreDir}/user-pin)" | atomic_write_secret 0400 "" ${pinEnvFile}
'';
};