From 9ca6e346d8d5f7c8f68f1d7b7586696fff819590 Mon Sep 17 00:00:00 2001 From: Laan Tungir Date: Sun, 3 May 2026 10:57:10 -0400 Subject: [PATCH] Harden dnsmasq setup and fix restart diagnostic exit codes --- update_and_deploy_fips.sh | 23 +++++++++++++++++------ 1 file changed, 17 insertions(+), 6 deletions(-) diff --git a/update_and_deploy_fips.sh b/update_and_deploy_fips.sh index 3867d71..a46b43c 100755 --- a/update_and_deploy_fips.sh +++ b/update_and_deploy_fips.sh @@ -200,7 +200,7 @@ restart_unit_with_diagnostics() { local output rc if command -v timeout >/dev/null 2>&1; then - if ! output="$(sudo timeout "${timeout_seconds}" systemctl restart "${unit}" 2>&1)"; then + output="$(sudo timeout "${timeout_seconds}" systemctl restart "${unit}" 2>&1)" || { rc=$? echo "Error: failed to restart ${unit} (exit ${rc})." >&2 if [[ ${rc} -eq 124 ]]; then @@ -213,9 +213,9 @@ restart_unit_with_diagnostics() { sudo journalctl -u "${unit}" -n "${journal_lines}" --no-pager >&2 || true [[ "${required}" == "yes" ]] && return 1 return 0 - fi + } else - if ! output="$(sudo systemctl restart "${unit}" 2>&1)"; then + output="$(sudo systemctl restart "${unit}" 2>&1)" || { rc=$? echo "Error: failed to restart ${unit} (exit ${rc})." >&2 [[ -n "${output}" ]] && printf '%s\n' "${output}" >&2 @@ -225,7 +225,7 @@ restart_unit_with_diagnostics() { sudo journalctl -u "${unit}" -n "${journal_lines}" --no-pager >&2 || true [[ "${required}" == "yes" ]] && return 1 return 0 - fi + } fi if ! sudo systemctl is-active --quiet "${unit}"; then @@ -259,6 +259,11 @@ ensure_dnsmasq_package() { echo "Warning: unable to auto-install dnsmasq on this distro." >&2 return 1 fi + + if ! command -v dnsmasq >/dev/null 2>&1; then + echo "Warning: dnsmasq command is still unavailable after package install." >&2 + return 1 + fi } configure_dnsmasq_fips_dns() { @@ -277,6 +282,7 @@ configure_dnsmasq_fips_dns() { fi echo "==> Configuring dnsmasq for .fips forwarding" + sudo mkdir -p "$(dirname "${conf_file}")" tmp_file="$(mktemp)" cat > "${tmp_file}" </dev/null 2>&1 || true - restart_unit_with_diagnostics "dnsmasq.service" "no" + if sudo systemctl list-unit-files dnsmasq.service --no-legend 2>/dev/null | grep -q '^dnsmasq\.service'; then + sudo systemctl enable dnsmasq.service >/dev/null 2>&1 || true + restart_unit_with_diagnostics "dnsmasq.service" "no" + else + echo "Warning: dnsmasq.service unit not found; install/enable dnsmasq manually." >&2 + return 1 + fi } ensure_build_toolchain