Files
mteehan 9c9f92ad04 fix: daemon /run spawn hardening, auth guard before first paint, WS refresh cap, interfaces runtime state
systemd: pre-create volatile /run paths so vacuum-walld's ProtectSystem=strict namespace setup cannot fail with 226/NAMESPACE — RuntimeDirectory=vacuum-wall nginx plus a tmpfiles.d spec (installed to /etc/tmpfiles.d/) covering /run/firewalld and /run/nginx.pid. Drop /run/sudo from ReadWritePaths: NOPASSWD children never need it, and its absence crash-looped restarts after sudo removed /run/sudo.

webui: run the auth session check before mounting the shell so logged-out visitors never flash the sidebar or a protected page; router guard and sidebar now react to auth state, and the login page renders full-bleed.

ws: cap refresh->reconnect episodes at 2 consecutive failures; if the WS path stays dead after a token refresh, abandon reconnection instead of looping refreshAuth forever (UI keeps working via REST until reload).

api: GET /api/network/interfaces now includes loopback and returns per-interface {config, runtime}; dashboard reads runtime.state (carrier counts as up) and the interfaces page filters lo client-side.

daemon: re-collect nginx state after lazy config migration (cached list went stale when the on-disk format changed under it), skip system_import.nginx when config.json already exists (re-parsing vacuum-wall's own generated sites is lossy), and poll nginx (60s) / acme (300s) state so file drift self-heals.
2026-08-19 15:32:36 +00:00

26 lines
1.5 KiB
Plaintext

# Volatile /run entries that must exist before vacuum-walld spawns.
#
# vacuum-walld runs with ProtectSystem=strict and lists these paths in
# ReadWritePaths=; if a ReadWritePaths= entry is missing at spawn time,
# systemd's mount-namespace setup fails (exit 226/NAMESPACE) and the unit
# crash-loops without ever creating data/daemon.sock. /run is a fresh tmpfs
# at every boot, so every /run path the unit references needs a boot-time
# creator. Status per path:
#
# /run/vacuum-wall, /run/nginx -> unit RuntimeDirectory= (daemon-owned)
# /run/firewalld -> this file (the firewalld unit only creates
# it while firewalld itself is running)
# /run/nginx.pid -> this file (nginx rewrites it on start; the
# daemon's `nginx -t` must be able to open
# it for writing inside its ProtectSystem=strict
# namespace, so it needs both a boot-time
# creator and a ReadWritePaths= entry)
# /run/sudo -> not referenced by the unit (see
# ReadWritePaths note in vacuum-walld.service);
# the sudo package ships its own tmpfiles spec
#
# Applied at early boot by systemd-tmpfiles-setup.service and by the install
# script (`systemd-tmpfiles --create`) for existing hosts.
d /run/firewalld 0750 root root -
f /run/nginx.pid 0644 root root -