Security & correctness fixes following the audit in REPORT.md.
- setup-hypervisor.sh: fix broken error handling — use curl -fsSL,
check failures properly, return valid exit codes, and fetch
/releases/latest (arch-aware) instead of the possibly-draft .[0]
- entrypoint.sh: quote "$@" and build --net conditionally so empty
NET_INTERFACE/NET_MAC don't yield "tap=,mac="
- image-updater: replace tight 3s retry loop with capped exponential
backoff + periodic pull instead of hammering the registry
- sshd: set PermitRootLogin prohibit-password explicitly (key-only root)
- vm.Dockerfile: copy only host private keys at mode 600 instead of
the whole secret/* glob (drops .gitkeep/.pub from /etc/ssh)
- Makefile: stop generating redundant _pub key files
- build-image.sh: detect failure via alpine-make-vm-image's real exit
status rather than grepping stdout for "ERROR"
- remove orphaned etc/alloy/config.alloy (service not installed)
- README: correct data.raw path
- add REPORT.md audit notes (H1/H2 accepted as out-of-scope)
65 lines
1.9 KiB
Bash
Executable File
65 lines
1.9 KiB
Bash
Executable File
#!/bin/sh
|
|
# Download and install the latest cloud-hypervisor + ch-remote static binaries.
|
|
set -eu
|
|
|
|
API="https://api.github.com/repos/cloud-hypervisor/cloud-hypervisor/releases/latest"
|
|
|
|
# Pick the asset matching this architecture.
|
|
case "$(uname -m)" in
|
|
x86_64|amd64)
|
|
ch_asset="cloud-hypervisor-static"
|
|
chremote_asset="ch-remote-static"
|
|
;;
|
|
aarch64|arm64)
|
|
ch_asset="cloud-hypervisor-static-aarch64"
|
|
chremote_asset="ch-remote-static-aarch64"
|
|
;;
|
|
*)
|
|
echo "unsupported architecture: $(uname -m)" >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
|
|
echo "fetching latest cloud-hypervisor release metadata"
|
|
if ! RESPONSE=$(curl -fsSL "$API"); then
|
|
echo "FAILED TO QUERY CLOUD-HYPERVISOR RELEASES API" >&2
|
|
exit 1
|
|
fi
|
|
|
|
HYPERVISOR_URL=$(printf '%s' "$RESPONSE" | jq -r --arg n "$ch_asset" \
|
|
'.assets[] | select(.name == $n) | .browser_download_url')
|
|
CH_REMOTE_URL=$(printf '%s' "$RESPONSE" | jq -r --arg n "$chremote_asset" \
|
|
'.assets[] | select(.name == $n) | .browser_download_url')
|
|
|
|
if [ -z "$HYPERVISOR_URL" ] || [ "$HYPERVISOR_URL" = "null" ] \
|
|
|| [ -z "$CH_REMOTE_URL" ] || [ "$CH_REMOTE_URL" = "null" ]; then
|
|
echo "FAILED TO RESOLVE DOWNLOAD URLS (asset missing for $(uname -m)?)" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# install_bin <url> <dest>
|
|
install_bin() {
|
|
_url="$1"; _dest="$2"
|
|
echo "downloading $_url"
|
|
if ! curl -fsSL -o "$_dest" "$_url"; then
|
|
echo "FAILED TO DOWNLOAD $_url" >&2
|
|
exit 1
|
|
fi
|
|
chmod +x "$_dest"
|
|
}
|
|
|
|
install_bin "$HYPERVISOR_URL" /usr/bin/cloud-hypervisor
|
|
install_bin "$CH_REMOTE_URL" /usr/bin/ch-remote
|
|
|
|
# Sanity-check the binaries actually run on this platform.
|
|
if ! /usr/bin/cloud-hypervisor --version >/dev/null 2>&1; then
|
|
echo "cloud-hypervisor is not executable (wrong arch?)" >&2
|
|
exit 1
|
|
fi
|
|
if ! /usr/bin/ch-remote --version >/dev/null 2>&1; then
|
|
echo "ch-remote is not executable (wrong arch?)" >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "cloud-hypervisor installed"
|