This commit is contained in:
2026-01-20 07:45:31 +02:00
parent 985f6f3fa7
commit 79a4e0d763
2 changed files with 44 additions and 0 deletions

View File

@@ -400,6 +400,35 @@
dev2_ssh_port: "{{ _local_port }}" dev2_ssh_port: "{{ _local_port }}"
changed_when: false changed_when: false
# -------------------- CHANGE 2: safety guard using dev2_mac (only if we actually discovered one) --------------------
- name: Read remote eth0 MAC via selected connection (guard: ensure this is DEV2)
when: dev2_conn_method == "tunnel" and dev2_passfile_used != "NONE" and (dev2_mac | default('') | trim | length > 0)
delegate_to: localhost
ansible.builtin.shell: |
set -e
HOST="{{ dev2_ssh_host }}"
PORT="{{ dev2_ssh_port }}"
sshpass -f "{{ dev2_passfile_used }}" ssh \
-o AddressFamily=inet \
-o StrictHostKeyChecking=no -o PubkeyAuthentication=no \
-o PreferredAuthentications=password -o NumberOfPasswordPrompts=1 \
-o ConnectTimeout=30 \
-p "$PORT" "{{ dev2_ssh_user }}@${HOST}" \
"cat /sys/class/net/eth0/address 2>/dev/null || echo"
args:
executable: /bin/bash
register: dev2_eth0_mac_read
changed_when: false
- name: Abort if remote eth0 MAC != discovered DEV2 MAC
when: dev2_conn_method == "tunnel" and dev2_passfile_used != "NONE" and (dev2_mac | default('') | trim | length > 0) and ((dev2_eth0_mac_read.stdout | default('') | trim | lower) != (dev2_mac | trim | lower))
ansible.builtin.fail:
msg: >
Safety stop: tunnel reached wrong device.
expected_dev2_mac={{ dev2_mac | trim }},
remote_eth0_mac={{ dev2_eth0_mac_read.stdout | default('') | trim }}.
# -------------------- CHANGE 2: safety guard using dev2_mac (only if we actually discovered one) -------------------- # -------------------- CHANGE 2: safety guard using dev2_mac (only if we actually discovered one) --------------------
- name: Read remote eth0 MAC via selected connection (guard: ensure this is DEV2) - name: Read remote eth0 MAC via selected connection (guard: ensure this is DEV2)
when: dev2_conn_method == "tunnel" and dev2_passfile_used != "NONE" and (dev2_mac | default('') | trim | length > 0) when: dev2_conn_method == "tunnel" and dev2_passfile_used != "NONE" and (dev2_mac | default('') | trim | length > 0)

View File

@@ -90,6 +90,12 @@
payload_encoding: "string" payload_encoding: "string"
changed_when: false changed_when: false
- name: "Wrapper | Mark host to skip full scan (cloud-offline)"
when: (wrapper_fail_line | default('') | length) > 0
set_fact:
wrapper_skip_full_scan: true
- name: "Wrapper | Stop host after cloud-offline journal (no full scan)" - name: "Wrapper | Stop host after cloud-offline journal (no full scan)"
when: (wrapper_fail_line | default('') | length) > 0 when: (wrapper_fail_line | default('') | length) > 0
meta: end_host meta: end_host
@@ -115,5 +121,14 @@
- name: "Wrapper | Reset SSH connection context (ensure new ansible_host is used)" - name: "Wrapper | Reset SSH connection context (ensure new ansible_host is used)"
meta: reset_connection meta: reset_connection
- name: Phase 3 gate | Skip full scan if cloud-offline
hosts: all
gather_facts: no
tasks:
- name: "Wrapper | Gate: end_host if wrapper_skip_full_scan is set"
when: wrapper_skip_full_scan | default(false)
meta: end_host
- import_playbook: sot-updater.yml - import_playbook: sot-updater.yml