Skip to content

Commit 4e98812

Browse files
author
Mayank Singh
committed
incorporate review comments
1 parent 4f6640a commit 4e98812

7 files changed

Lines changed: 10 additions & 135 deletions

File tree

‎acl/SPECS/walinuxagent-acl-config/10-waagent-sysext.conf‎

Lines changed: 0 additions & 13 deletions
This file was deleted.

‎acl/SPECS/walinuxagent-acl-config/waagent.conf‎

Lines changed: 0 additions & 37 deletions
This file was deleted.

‎acl/SPECS/walinuxagent-acl-config/waagent.service‎

Lines changed: 0 additions & 18 deletions
This file was deleted.

‎acl/SPECS/walinuxagent-acl-config/walinuxagent-acl-config.signatures.json‎

Lines changed: 0 additions & 8 deletions
This file was deleted.

‎acl/SPECS/walinuxagent-acl-config/walinuxagent-acl-config.spec‎

Lines changed: 0 additions & 58 deletions
This file was deleted.

‎acl/packages.yaml‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,4 +30,3 @@ packages:
3030
- runc # Pre-merge validation of Azure Linux container runtime changes
3131
- selinux-policy # SELinux reference policy (ACL-specific modules)
3232
- trident # Declarative OS lifecycle agent; built here for the acl-pipelines tridentRpmSource=sdk option
33-
- walinuxagent-acl-config # Prevent waagent from activating sshd.service

‎sdk_container/src/third_party/coreos-overlay/coreos-base/oem-azure/files/manglefs_rpm.sh‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,16 @@ if [[ -f "${rootfs}/usr/lib/systemd/system/waagent.service" ]]; then
2525
sed -i \
2626
'/^\[Service\]$/a ExecStartPre=/bin/bash -c '\''if [[ ! -e /oem/waagent.conf ]]; then ln -sf /etc/waagent.conf /oem/waagent.conf; fi'\''' \
2727
"${rootfs}/usr/lib/systemd/system/waagent.service"
28+
29+
# SSH is socket-activated, so this Wants= revives sshd once a node disables SSH.
30+
sed -i -E '/^Wants=/ s/[[:space:]]*\bsshd\.service\b//' \
31+
"${rootfs}/usr/lib/systemd/system/waagent.service"
32+
33+
if grep -qE '^Wants=.*\bsshd\.service\b' "${rootfs}/usr/lib/systemd/system/waagent.service" ||
34+
! grep -qE '^Wants=.*sshd-keygen\.service' "${rootfs}/usr/lib/systemd/system/waagent.service"; then
35+
echo "ERROR: unexpected waagent.service Wants= after mangle" >&2
36+
exit 1
37+
fi
2838
fi
2939

3040
# Create chrony sub-dir if it doesn't exist

0 commit comments

Comments
 (0)