feat(k1): stabilize LAB bridge and isolate onboard device integration
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
#!/usr/bin/python3 -I
|
||||
"""Administrator-only import of the exact application key from protected stdin."""
|
||||
import os
|
||||
import subprocess
|
||||
import sys
|
||||
import tempfile
|
||||
from pathlib import Path
|
||||
|
||||
if os.geteuid() != 0 or len(sys.argv) != 1:
|
||||
raise SystemExit("Root stdin import required")
|
||||
secret = bytearray(sys.stdin.buffer.read(1025).strip())
|
||||
try:
|
||||
if len(secret) != 36 or any(v < 33 or v > 126 for v in secret):
|
||||
raise SystemExit("Credential does not match the reviewed K1 profile")
|
||||
root = Path("/etc/credstore.encrypted")
|
||||
root.mkdir(mode=0o700, exist_ok=True)
|
||||
if root.is_symlink() or root.stat().st_uid != 0 or root.stat().st_mode & 0o022:
|
||||
raise SystemExit("Unsafe credential store")
|
||||
path = root / "k1-application"
|
||||
if path.is_symlink() or path.exists():
|
||||
raise SystemExit("K1 credential already installed; explicit rotation required")
|
||||
with tempfile.TemporaryDirectory(prefix=".k1-", dir=root) as directory:
|
||||
staged = Path(directory) / "encrypted"
|
||||
completed = subprocess.run(
|
||||
["/usr/bin/systemd-creds", "encrypt", "--name=k1-application", "--with-key=host", "-", str(staged)],
|
||||
input=secret, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, timeout=30,
|
||||
)
|
||||
if completed.returncode:
|
||||
raise SystemExit("K1 credential import failed")
|
||||
staged.chmod(0o600)
|
||||
with staged.open("rb") as stream:
|
||||
os.fsync(stream.fileno())
|
||||
# Atomic publication without overwriting a concurrently installed key.
|
||||
os.link(staged, path)
|
||||
finally:
|
||||
secret[:] = b"\0" * len(secret)
|
||||
Reference in New Issue
Block a user