Harden dnsmasq setup and fix restart diagnostic exit codes
This commit is contained in:
@@ -200,7 +200,7 @@ restart_unit_with_diagnostics() {
|
||||
local output rc
|
||||
|
||||
if command -v timeout >/dev/null 2>&1; then
|
||||
if ! output="$(sudo timeout "${timeout_seconds}" systemctl restart "${unit}" 2>&1)"; then
|
||||
output="$(sudo timeout "${timeout_seconds}" systemctl restart "${unit}" 2>&1)" || {
|
||||
rc=$?
|
||||
echo "Error: failed to restart ${unit} (exit ${rc})." >&2
|
||||
if [[ ${rc} -eq 124 ]]; then
|
||||
@@ -213,9 +213,9 @@ restart_unit_with_diagnostics() {
|
||||
sudo journalctl -u "${unit}" -n "${journal_lines}" --no-pager >&2 || true
|
||||
[[ "${required}" == "yes" ]] && return 1
|
||||
return 0
|
||||
fi
|
||||
}
|
||||
else
|
||||
if ! output="$(sudo systemctl restart "${unit}" 2>&1)"; then
|
||||
output="$(sudo systemctl restart "${unit}" 2>&1)" || {
|
||||
rc=$?
|
||||
echo "Error: failed to restart ${unit} (exit ${rc})." >&2
|
||||
[[ -n "${output}" ]] && printf '%s\n' "${output}" >&2
|
||||
@@ -225,7 +225,7 @@ restart_unit_with_diagnostics() {
|
||||
sudo journalctl -u "${unit}" -n "${journal_lines}" --no-pager >&2 || true
|
||||
[[ "${required}" == "yes" ]] && return 1
|
||||
return 0
|
||||
fi
|
||||
}
|
||||
fi
|
||||
|
||||
if ! sudo systemctl is-active --quiet "${unit}"; then
|
||||
@@ -259,6 +259,11 @@ ensure_dnsmasq_package() {
|
||||
echo "Warning: unable to auto-install dnsmasq on this distro." >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
if ! command -v dnsmasq >/dev/null 2>&1; then
|
||||
echo "Warning: dnsmasq command is still unavailable after package install." >&2
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
configure_dnsmasq_fips_dns() {
|
||||
@@ -277,6 +282,7 @@ configure_dnsmasq_fips_dns() {
|
||||
fi
|
||||
|
||||
echo "==> Configuring dnsmasq for .fips forwarding"
|
||||
sudo mkdir -p "$(dirname "${conf_file}")"
|
||||
tmp_file="$(mktemp)"
|
||||
cat > "${tmp_file}" <<EOF
|
||||
# Managed by update_and_deploy_fips.sh
|
||||
@@ -313,8 +319,13 @@ EOF
|
||||
fi
|
||||
fi
|
||||
|
||||
sudo systemctl enable dnsmasq.service >/dev/null 2>&1 || true
|
||||
restart_unit_with_diagnostics "dnsmasq.service" "no"
|
||||
if sudo systemctl list-unit-files dnsmasq.service --no-legend 2>/dev/null | grep -q '^dnsmasq\.service'; then
|
||||
sudo systemctl enable dnsmasq.service >/dev/null 2>&1 || true
|
||||
restart_unit_with_diagnostics "dnsmasq.service" "no"
|
||||
else
|
||||
echo "Warning: dnsmasq.service unit not found; install/enable dnsmasq manually." >&2
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
ensure_build_toolchain
|
||||
|
||||
Reference in New Issue
Block a user