Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
893b686c15 | ||
|
|
40557ffb74 |
1 changed files with 44 additions and 4 deletions
|
|
@ -170,13 +170,53 @@ in
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
install -d -m 0755 ${dir}
|
install -d -m 0755 ${dir}
|
||||||
tmp=${bundlePath}.tmp
|
tmp=${bundlePath}.tmp
|
||||||
cat /etc/ssl/certs/ca-certificates.crt ${source} > "$tmp"
|
# Count the HIVE half on its own, before assembling.
|
||||||
# `cat` of an empty or missing-but-mounted source exits 0, so the
|
#
|
||||||
# result has to be inspected rather than the command trusted.
|
# Inspecting the assembled file cannot work: the system store
|
||||||
if ! grep -q 'BEGIN CERTIFICATE' "$tmp"; then
|
# always holds certificates, so "does the result contain a
|
||||||
echo "${unit}: assembled bundle contains no certificate" >&2
|
# certificate" passes unconditionally — including in the one case
|
||||||
|
# worth catching, where this source contributed nothing. And the
|
||||||
|
# public CAs are irrelevant to what this bundle is for: every name
|
||||||
|
# the consumer verifies is issued by our own CA, so a bundle of
|
||||||
|
# nothing but public CAs is, for this purpose, an empty one that
|
||||||
|
# measures as full.
|
||||||
|
#
|
||||||
|
# One helper, because the safe form is not the obvious one and
|
||||||
|
# three copies of a subtle idiom is three chances to get it wrong.
|
||||||
|
#
|
||||||
|
# `grep -c` has two different zero-ish outcomes and `set -e` is
|
||||||
|
# on: an EMPTY file prints `0` and exits 1, a MISSING file prints
|
||||||
|
# nothing and exits 2. So `|| true` leaves the variable empty on
|
||||||
|
# the second — the `-eq` then dies with "integer expected"
|
||||||
|
# instead of reporting — and `|| echo 0` appends a second zero on
|
||||||
|
# the first, yielding `00`. Normalising afterwards is the only
|
||||||
|
# form that survives both.
|
||||||
|
certs() {
|
||||||
|
n=$(grep -c 'BEGIN CERTIFICATE' "$1" 2>/dev/null || true)
|
||||||
|
if [ -z "$n" ]; then n=0; fi
|
||||||
|
printf '%s' "$n"
|
||||||
|
}
|
||||||
|
contributed=$(certs ${source})
|
||||||
|
if [ "$contributed" -eq 0 ]; then
|
||||||
|
echo "${unit}: ${source} contributed no certificate to the bundle" >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
system=$(certs /etc/ssl/certs/ca-certificates.crt)
|
||||||
|
cat /etc/ssl/certs/ca-certificates.crt ${source} > "$tmp"
|
||||||
|
# `cat` of a source truncated between the count and the copy still
|
||||||
|
# exits 0, so the result is checked against what both halves
|
||||||
|
# brought rather than merely for being non-empty.
|
||||||
|
total=$(certs "$tmp")
|
||||||
|
if [ "$total" -ne $((system + contributed)) ]; then
|
||||||
|
echo "${unit}: bundle has $total certificates, expected $system + $contributed" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
# ⚠️ Scope: this proves the anchor was CONTRIBUTED, not that it is
|
||||||
|
# USABLE. A consumer that reads only the first certificate of the
|
||||||
|
# file ignores it anyway — that is what took the swarm collector
|
||||||
|
# down — and no check on this file can see it. Only a real
|
||||||
|
# handshake can. Do not read a green assembly as a working trust
|
||||||
|
# store.
|
||||||
chmod 0644 "$tmp"
|
chmod 0644 "$tmp"
|
||||||
mv "$tmp" ${bundlePath}
|
mv "$tmp" ${bundlePath}
|
||||||
'';
|
'';
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue