mirror of
https://github.com/m8tin/cis.git
synced 2026-08-01 11:47:31 +02:00
Used REGEX for composition sync
This commit is contained in:
+3
-3
@@ -23,9 +23,9 @@ function base.checkAllInputParameters() {
|
|||||||
_SUCCESS="true"
|
_SUCCESS="true"
|
||||||
for _ARG in "${@}"; do
|
for _ARG in "${@}"; do
|
||||||
if [ -n "${_ARG}" ]; then
|
if [ -n "${_ARG}" ]; then
|
||||||
# Has to start with an alphanumeric char '--' or '/'
|
# Has to start with an alphanumeric char '--', '/' or '@'
|
||||||
if [[ ! "${_ARG}" =~ ^(--|/)?[[:alnum:]] ]]; then
|
if [[ ! "${_ARG}" =~ ^(--|/|@)?[[:alnum:]] ]]; then
|
||||||
echo "❌ Security base.checkAllInputParameters(): No special characters except '--' or '/' are allowed at the beginning of a parameter: '${_ARG}'" >&2
|
echo "❌ Security base.checkAllInputParameters(): No special characters except '--', '/' or '@' are allowed at the beginning of a parameter: '${_ARG}'" >&2
|
||||||
_SUCCESS="false"
|
_SUCCESS="false"
|
||||||
fi
|
fi
|
||||||
# No forbidden character is allowed to remain
|
# No forbidden character is allowed to remain
|
||||||
|
|||||||
@@ -6,6 +6,6 @@ Cmnd_Alias C_COMPOSITION_SYNC = \
|
|||||||
^[a-zA-Z0-9][a-zA-Z0-9.-]* \
|
^[a-zA-Z0-9][a-zA-Z0-9.-]* \
|
||||||
[a-zA-Z][a-zA-Z0-9/_-]*[a-zA-Z0-9] \
|
[a-zA-Z][a-zA-Z0-9/_-]*[a-zA-Z0-9] \
|
||||||
[a-zA-Z0-9][a-zA-Z0-9_-]* \
|
[a-zA-Z0-9][a-zA-Z0-9_-]* \
|
||||||
([a-zA-Z0-9][a-zA-Z0-9._:-]*)? \
|
(@[a-zA-Z0-9][a-zA-Z0-9._:-]*)? \
|
||||||
([a-zA-Z0-9][a-zA-Z0-9._:-]*)?$
|
([a-zA-Z0-9][a-zA-Z0-9._:-]*)?$
|
||||||
composition-sync ALL = (root) NOPASSWD: C_COMPOSITION_SYNC
|
composition-sync ALL = (root) NOPASSWD: C_COMPOSITION_SYNC
|
||||||
|
|||||||
@@ -130,14 +130,14 @@ function send() {
|
|||||||
# Parameter 3: Only alphanumeric characters allowed and [.-] if not leading (due to: -oProxyCommand=...).
|
# Parameter 3: Only alphanumeric characters allowed and [.-] if not leading (due to: -oProxyCommand=...).
|
||||||
# Parameter 4: Only alphanumeric characters allowed and [._:-] if not leading (due to: -oProxyCommand=...), but can be empty.
|
# Parameter 4: Only alphanumeric characters allowed and [._:-] if not leading (due to: -oProxyCommand=...), but can be empty.
|
||||||
# Parameter 5: Only alphanumeric characters allowed and [._:-] if not leading (due to: -oProxyCommand=...), but can be empty.
|
# Parameter 5: Only alphanumeric characters allowed and [._:-] if not leading (due to: -oProxyCommand=...), but can be empty.
|
||||||
base.set RECEIVERHOST "${1}" '^[a-zA-Z0-9][a-zA-Z0-9._-]*$'
|
base.set RECEIVERHOST "${1}" "${REGEX[HOST]}"
|
||||||
base.set ZFS_BRANCH "${2}" '^[a-zA-Z][a-zA-Z0-9/_-]*[a-zA-Z0-9]$'
|
base.set ZFS_BRANCH "${2}" "${REGEX[ZFS]}"
|
||||||
base.set COMPOSITION "${3}" '^[a-zA-Z0-9][a-zA-Z0-9.-]*$'
|
base.set COMPOSITION "${3}" "${REGEX[COMPOSITION]}"
|
||||||
base.set RECEIVERS_SNAPSHOT "${4}" '^[a-zA-Z0-9][a-zA-Z0-9._:-]*$' optional
|
base.set RECEIVERS_SNAPSHOT "${4}" "${REGEX[SNAPSHOT]}" optional
|
||||||
base.set RESUME_TOKEN "${5}" '^[a-zA-Z0-9][a-zA-Z0-9._:-]*$' optional
|
base.set RESUME_TOKEN "${5}" '^[a-zA-Z0-9][a-zA-Z0-9._:-]*$' optional
|
||||||
|
|
||||||
# Resume mode
|
# Resume mode
|
||||||
if [ "${RECEIVERS_SNAPSHOT}" == "RESUME" ]; then
|
if [ "${RECEIVERS_SNAPSHOT}" == "@RESUME" ] && [ -n "${RESUME_TOKEN}" ]; then
|
||||||
sendResume "${RESUME_TOKEN}"
|
sendResume "${RESUME_TOKEN}"
|
||||||
|
|
||||||
# Exit preserving the code
|
# Exit preserving the code
|
||||||
|
|||||||
@@ -108,7 +108,7 @@ function receive() {
|
|||||||
_RESUME_TOKEN=$(zfs get -H -o value receive_resume_token "${_ZFS}" 2> /dev/null)
|
_RESUME_TOKEN=$(zfs get -H -o value receive_resume_token "${_ZFS}" 2> /dev/null)
|
||||||
if [ -n "${_RESUME_TOKEN}" ] && [ "${_RESUME_TOKEN}" != "-" ]; then
|
if [ -n "${_RESUME_TOKEN}" ] && [ "${_RESUME_TOKEN}" != "-" ]; then
|
||||||
echo "Resume token present trying to resume at ${_RESUME_TOKEN}"
|
echo "Resume token present trying to resume at ${_RESUME_TOKEN}"
|
||||||
_COMMON_SNAPSHOT="RESUME"
|
_COMMON_SNAPSHOT="@RESUME"
|
||||||
else
|
else
|
||||||
_RESUME_TOKEN=""
|
_RESUME_TOKEN=""
|
||||||
_COMMON_SNAPSHOT=$(zfs list -H -o name -S creation -t snapshot "${_ZFS}" 2> /dev/null | head -n 1)
|
_COMMON_SNAPSHOT=$(zfs list -H -o name -S creation -t snapshot "${_ZFS}" 2> /dev/null | head -n 1)
|
||||||
@@ -118,13 +118,14 @@ function receive() {
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
# Add "-s" for resumable streams in the next line at zfs receive. Not done yet because of: cannot receive resume stream: kernel modules must be upgraded to receive this stream.
|
# Add "-s" for resumable streams in the next line at zfs receive. Not done yet because of: cannot receive resume stream: kernel modules must be upgraded to receive this stream.
|
||||||
${_SSH_COMMAND} "sudo ${_SEND_SCRIPT:?"Missing SEND_SCRIPT"} \"${_RECEIVERHOST}\" \"${_ZFS_BRANCH}\" \"${_COMPOSITION}\" \"${_COMMON_SNAPSHOT#${_ZFS}@}\" \"${_RESUME_TOKEN}\"" | zfs receive -v "${_ZFS}"
|
${_SSH_COMMAND} "sudo ${_SEND_SCRIPT:?"Missing SEND_SCRIPT"} \"${_RECEIVERHOST}\" \"${_ZFS_BRANCH}\" \"${_COMPOSITION}\" \"@${_COMMON_SNAPSHOT#*@}\" \"${_RESUME_TOKEN}\"" | zfs receive -v "${_ZFS}"
|
||||||
if [ $? -ne 0 ]; then
|
if [ $? -ne 0 ]; then
|
||||||
echo "Unable to receive stream using these settings:"
|
echo "Unable to receive stream using these settings:"
|
||||||
echo " - Sending host: ${_SOURCEHOST}:${_SSH_PORT}"
|
echo " - Sending host: ${_SOURCEHOST}:${_SSH_PORT}"
|
||||||
echo " - Receiving host: ${_RECEIVERHOST}"
|
echo " - Receiving host: ${_RECEIVERHOST}"
|
||||||
|
echo " - ZFS Branch: ${_ZFS_BRANCH}"
|
||||||
echo " - Composition: ${_COMPOSITION}"
|
echo " - Composition: ${_COMPOSITION}"
|
||||||
echo " - Offered snapshot: ${_ZFS}@${_COMMON_SNAPSHOT#${_ZFS}@}"
|
echo " - Offered snapshot: @${_COMMON_SNAPSHOT#*@}"
|
||||||
echo " - Resume token: ${_RESUME_TOKEN}"
|
echo " - Resume token: ${_RESUME_TOKEN}"
|
||||||
echo "Current state of snapshots:"
|
echo "Current state of snapshots:"
|
||||||
zfs list -t snapshot "${_ZFS}" 2> /dev/null | tail
|
zfs list -t snapshot "${_ZFS}" 2> /dev/null | tail
|
||||||
|
|||||||
Reference in New Issue
Block a user