fix(auth): harden restore verification transaction
This commit is contained in:
@@ -104,20 +104,43 @@ func restoreWithDependencies(ctx context.Context, installation config.Installati
|
||||
return result, err
|
||||
}
|
||||
mutated := false
|
||||
maintenanceAttempted := false
|
||||
stopAttempted := false
|
||||
defer func() {
|
||||
if resultErr != nil && mutated {
|
||||
if recoveryErr := deps.recover(context.Background(), installation, recovery, wasRunning); recoveryErr != nil {
|
||||
resultErr = errors.Join(resultErr, fmt.Errorf("restore recovery checkpoint: %w", recoveryErr))
|
||||
} else {
|
||||
stopAttempted = false
|
||||
}
|
||||
}
|
||||
if maintenanceAttempted {
|
||||
cleanupContext := context.Background()
|
||||
if wasRunning && stopAttempted {
|
||||
if startErr := composeStartAndVerify(cleanupContext, installation, deps.runner); startErr != nil {
|
||||
resultErr = errors.Join(resultErr, fmt.Errorf("restore maintenance cleanup restart: %w", startErr))
|
||||
} else {
|
||||
stopAttempted = false
|
||||
}
|
||||
}
|
||||
if deactivateErr := maintenance(cleanupContext, installation, deps.runner, false); deactivateErr != nil {
|
||||
resultErr = errors.Join(resultErr, fmt.Errorf("restore maintenance cleanup: %w", deactivateErr))
|
||||
}
|
||||
}
|
||||
}()
|
||||
if wasRunning {
|
||||
// The activation command may take effect even when its response is lost. Track the attempt,
|
||||
// not merely a successful return, so every subsequent path removes the admissions barrier.
|
||||
maintenanceAttempted = true
|
||||
if err := maintenance(ctx, installation, deps.runner, true); err != nil {
|
||||
return result, err
|
||||
}
|
||||
if err := waitForNoActiveSessions(ctx, installation, deps.runner, request.Drain, deps.sleep); err != nil {
|
||||
return result, err
|
||||
}
|
||||
// Compose may stop the core and then lose its response. Cleanup must therefore restart after
|
||||
// any stop attempt, including a command that returns an error.
|
||||
stopAttempted = true
|
||||
if err := runCompose(ctx, installation, deps.runner, "stop"); err != nil {
|
||||
return result, err
|
||||
}
|
||||
@@ -133,7 +156,12 @@ func restoreWithDependencies(ctx context.Context, installation config.Installati
|
||||
if err := composeStartAndVerify(ctx, installation, deps.runner); err != nil {
|
||||
return result, err
|
||||
}
|
||||
stopAttempted = false
|
||||
result.Restarted = true
|
||||
if err := maintenance(ctx, installation, deps.runner, false); err != nil {
|
||||
return result, err
|
||||
}
|
||||
maintenanceAttempted = false
|
||||
}
|
||||
for _, name := range []string{"health", "doctor", "pi", "workspace"} {
|
||||
check := deps.verify[name]
|
||||
|
||||
Reference in New Issue
Block a user