forked from heavy-duty/box
The original diff claimed all three sibling `ufw status | grep -q` sites were safe because none set pipefail. That is true of drill/wipe.sh and drill/doctor.sh (both `set -u`) and FALSE of host/teardown-host.sh, whose line 12 is `set -euo pipefail`. Its line 60 was the identical pipeline, so the same race could read a plainly-active UFW as inactive and skip the whole crumb-removal block — leaving stale boxnet/claudenet rules on a host the operator was told is clean. Its numbered-delete loop had the same early-exit reader as its condition, so it could also end while rules remained. Both now read captures, matching box-firewall.sh's fix. The changelog claim is corrected rather than deleted: this repo's changelog is the record of what was proven, and shipping a disproven safety claim about a live defect is worse than the defect, because it tells the next reader not to look. Pinned in both directions, with comment lines stripped before matching — the fix's own commentary quotes the racing shape to explain it, and a pin that cannot tell prose from code fails on the comment documenting why it exists. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| box-firewall.service | ||
| box-firewall.sh | ||
| grant-user.sh | ||
| migrate-host.sh | ||
| revoke-user.sh | ||
| setup-host.sh | ||
| teardown-host.sh | ||