deploy.sh: probe NOPASSWD sudo before falling back to interactive validate
`sudo -v` always attempts interactive credential validation; it does not consult NOPASSWD entries. On any user configured with `NOPASSWD:ALL` (cloud-init's default ubuntu, most CI runners), `sudo -v` still demands a TTY password prompt and dies with "sudo authentication failed" when there is no TTY. Found by the obmp-portability-test two-VM run: deploy.sh failed at line 433 on a cloud-init-provisioned Ubuntu 24.04 VM despite the ubuntu user having passwordless sudo (`sudo -n whoami` returned root correctly). Fix: try `sudo -n -v` first (succeeds silently on NOPASSWD users, fails non-interactively on others), and only fall through to the interactive `sudo -v` prompt when the non-interactive probe fails. Humans still get the same visible up-front prompt; automation now succeeds without one. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
parent
5b5593b6cc
commit
bb71c9f6fd
12
deploy.sh
12
deploy.sh
@ -426,11 +426,19 @@ fi
|
|||||||
|
|
||||||
# Prime sudo early if filesystem setup will need it, so the password prompt
|
# Prime sudo early if filesystem setup will need it, so the password prompt
|
||||||
# happens HERE (visible, at the start) instead of blocking mid-provision.
|
# happens HERE (visible, at the start) instead of blocking mid-provision.
|
||||||
|
# `sudo -v` alone ALWAYS attempts interactive validation -- it does not
|
||||||
|
# consult NOPASSWD -- so it fails without a TTY (cloud-init, ansible without
|
||||||
|
# a pty, unattended CI). Try `-n -v` first: on a NOPASSWD user it succeeds
|
||||||
|
# silently; otherwise we fall through to the interactive prompt for humans.
|
||||||
_dr_probe="$(get_env OBMP_DATA_ROOT)"; _dr_probe="${_dr_probe:-/var/openbmp}"
|
_dr_probe="$(get_env OBMP_DATA_ROOT)"; _dr_probe="${_dr_probe:-/var/openbmp}"
|
||||||
if [ ! -w "$(dirname "$_dr_probe")" ] || { [ -d "$_dr_probe" ] && [ ! -w "$_dr_probe" ]; }; then
|
if [ ! -w "$(dirname "$_dr_probe")" ] || { [ -d "$_dr_probe" ] && [ ! -w "$_dr_probe" ]; }; then
|
||||||
if [ "$(id -u)" -ne 0 ]; then
|
if [ "$(id -u)" -ne 0 ]; then
|
||||||
log "Filesystem setup under $_dr_probe needs sudo - authenticating now."
|
if sudo -n -v 2>/dev/null; then
|
||||||
sudo -v || die "sudo authentication failed"
|
log "Filesystem setup under $_dr_probe needs sudo - passwordless sudo OK."
|
||||||
|
else
|
||||||
|
log "Filesystem setup under $_dr_probe needs sudo - authenticating now."
|
||||||
|
sudo -v || die "sudo authentication failed"
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user