host-modules: convert swarm-bao's HSM-PIN env writer to atomic_write_secret
swarm-bao-token's pin.env write (the BAO_HSM_PIN EnvironmentFile for
openbao's pkcs11 seal) had the same write-then-chmod-on-live-path
shape as the sites already converted: printf > path directly on the
live file, chmod after. Same fix, same helper. Content
("BAO_HSM_PIN=<user-pin>\n") and final mode (0400, root-owned — no
chown, same as before) are unchanged; pin.env stays at the same path,
so openbao's EnvironmentFile= reference needs no change.
Refs #4723
This commit is contained in:
parent
5466cec066
commit
7a9fadc21a
1 changed files with 4 additions and 2 deletions
|
|
@ -2595,6 +2595,9 @@ in
|
|||
};
|
||||
script = ''
|
||||
set -euo pipefail
|
||||
|
||||
${atomicWriteSecret}
|
||||
|
||||
install -d -m 0770 -g ${tokenGroup} ${tokenStoreDir}
|
||||
# Required whenever the store is not at its default location, or the
|
||||
# library cannot find the token the seal asks for.
|
||||
|
|
@ -2644,8 +2647,7 @@ in
|
|||
chgrp ${tokenGroup} ${tokenStoreDir}/tpm2_pkcs11.sqlite3
|
||||
chmod 0660 ${tokenStoreDir}/tpm2_pkcs11.sqlite3
|
||||
|
||||
( umask 077; printf 'BAO_HSM_PIN=%s\n' "$(cat ${tokenStoreDir}/user-pin)" > ${pinEnvFile} )
|
||||
chmod 0400 ${pinEnvFile}
|
||||
printf 'BAO_HSM_PIN=%s\n' "$(cat ${tokenStoreDir}/user-pin)" | atomic_write_secret 0400 "" ${pinEnvFile}
|
||||
'';
|
||||
};
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue