Commit 3949a9f
committed
fix(node): sanitize systemd backup secrets
Remove file-backed managed systemd environment keys from .bak units during restage so upgrades from inline-token units do not preserve leaked gateway tokens.
Add regression coverage for restaging over a vulnerable unit while preserving unrelated environment entries.1 parent 59aabf6 commit 3949a9f
2 files changed
Lines changed: 71 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
877 | 877 | | |
878 | 878 | | |
879 | 879 | | |
| 880 | + | |
| 881 | + | |
| 882 | + | |
| 883 | + | |
| 884 | + | |
| 885 | + | |
| 886 | + | |
| 887 | + | |
| 888 | + | |
| 889 | + | |
| 890 | + | |
| 891 | + | |
| 892 | + | |
| 893 | + | |
| 894 | + | |
| 895 | + | |
| 896 | + | |
| 897 | + | |
| 898 | + | |
| 899 | + | |
| 900 | + | |
| 901 | + | |
| 902 | + | |
| 903 | + | |
| 904 | + | |
| 905 | + | |
| 906 | + | |
| 907 | + | |
| 908 | + | |
| 909 | + | |
| 910 | + | |
| 911 | + | |
| 912 | + | |
| 913 | + | |
| 914 | + | |
| 915 | + | |
| 916 | + | |
| 917 | + | |
| 918 | + | |
| 919 | + | |
| 920 | + | |
880 | 921 | | |
881 | 922 | | |
882 | 923 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
231 | 231 | | |
232 | 232 | | |
233 | 233 | | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
234 | 255 | | |
235 | 256 | | |
236 | 257 | | |
| |||
593 | 614 | | |
594 | 615 | | |
595 | 616 | | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
596 | 620 | | |
597 | 621 | | |
598 | 622 | | |
599 | 623 | | |
600 | | - | |
601 | 624 | | |
602 | | - | |
| 625 | + | |
| 626 | + | |
| 627 | + | |
| 628 | + | |
| 629 | + | |
| 630 | + | |
603 | 631 | | |
604 | 632 | | |
605 | 633 | | |
| |||
620 | 648 | | |
621 | 649 | | |
622 | 650 | | |
623 | | - | |
624 | | - | |
625 | | - | |
626 | 651 | | |
627 | 652 | | |
628 | 653 | | |
| |||
0 commit comments