v0.7.1: walk the ladder once ever — persistent learned modes, rule pins, same-boot iPXE recovery
Answers the operational question 'can a machine try all three boot binaries in one go?' The protocol can't carry three NBPs in one cycle (one boot file per DHCP round, the Secure-Boot refusal happens after handoff with no error report, and the broken-NIC case specifically needs the firmware itself to load builtin-driver iPXE — GRUB's network rides the same broken firmware stack). What we CAN do is make the walk a once-per-machine-ever event and give operators a way to skip it: - Learned driver modes persist (<work_dir>/driver_modes.json). A MAC that reaches the Shim rung, or confirms an iPXE handoff at Builtin, is pinned to disk: immune to the 30-min TTL, reloaded at startup. The file only carries exceptions — a healthy fleet never writes it. Corrupt file starts empty (standard crash-cache policy). - Boot rules gain an optional driver_mode pin (auto/firmware/builtin/ shim), consulted by the DHCP proxy BEFORE the escalation ladder: 'this OUI is a Secure Boot rack -> serve shim immediately' = zero failed cycles. Mode-only rules coexist with target rules (a pin doesn't shadow a later target match). Editor column on Hosts tab. - grub.cfg now tries to chainload all-drivers iPXE before showing the signed menu: with SB off the chainload succeeds and the client gets the full iPXE feature set back in the SAME boot (self-healing for mis-escalations, and the handoff then pins the working mode); with SB on, shim's verifier refuses it inline — no reboot — and the signed menu appears. DhcpProxyServer now takes the escalation table + rules store from main (persistence path comes from the configured work dir). Validation: clippy clean, fmt clean, 299 workspace tests green (+9: persistence round-trip across restart, Shim pin survives TTL, learned Builtin survives TTL, corrupt-file recovery, default-mode-never- persisted, rule-pin matching incl. unknown-mode tolerance and pin/target coexistence, GRUB chainload-before-menu ordering, API round-trip of the driver_mode field). Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
3a32d65fb7
commit
29040e8a5a
@@ -41,7 +41,16 @@ pub struct BootRule {
|
||||
pub arch: String,
|
||||
/// Boot entry id (a `BootEntry::id`) or reserved menu name
|
||||
/// (`_local`, `_queue`, …) to chain to when this rule matches.
|
||||
/// May be empty for a rule that only pins a driver mode.
|
||||
#[serde(default)]
|
||||
pub target: String,
|
||||
/// v0.7.1: optional first-boot binary pin — `""` (auto: let the
|
||||
/// escalation ladder decide), `"firmware"`, `"builtin"`, or
|
||||
/// `"shim"`. Lets an operator declare "this rack is all Secure
|
||||
/// Boot → serve the signed chain immediately", skipping the
|
||||
/// learn-by-failing walk entirely for known fleets.
|
||||
#[serde(default)]
|
||||
pub driver_mode: String,
|
||||
/// Rules can be parked without deleting them.
|
||||
#[serde(default = "default_true")]
|
||||
pub enabled: bool,
|
||||
@@ -111,6 +120,7 @@ impl BootRulesStore {
|
||||
r.mac_prefix = normalize_mac(&r.mac_prefix);
|
||||
r.arch = r.arch.trim().to_ascii_lowercase();
|
||||
r.target = r.target.trim().to_string();
|
||||
r.driver_mode = r.driver_mode.trim().to_ascii_lowercase();
|
||||
r.note = r.note.trim().to_string();
|
||||
}
|
||||
cfg.webhook_url = cfg.webhook_url.trim().to_string();
|
||||
@@ -134,10 +144,40 @@ impl BootRulesStore {
|
||||
/// passed one along, `None` otherwise (older chains).
|
||||
#[must_use]
|
||||
pub fn match_target(&self, mac: &str, arch: Option<&str>) -> Option<String> {
|
||||
self.first_match(mac, arch, |r| {
|
||||
(!r.target.is_empty()).then(|| r.target.clone())
|
||||
})
|
||||
}
|
||||
|
||||
/// v0.7.1: first enabled rule that pins a driver mode for `(mac,
|
||||
/// arch)`. Consulted by the DHCP proxy *before* the automatic
|
||||
/// escalation ladder — an operator who knows a rack is all Secure
|
||||
/// Boot pins it to `shim` and those machines never walk the ladder.
|
||||
/// Unknown mode strings are ignored (forward compatibility).
|
||||
#[must_use]
|
||||
pub fn driver_mode_hint(&self, mac: &str, arch: Option<&str>) -> Option<crate::DriverMode> {
|
||||
self.first_match(mac, arch, |r| match r.driver_mode.as_str() {
|
||||
"firmware" => Some(crate::DriverMode::Firmware),
|
||||
"builtin" => Some(crate::DriverMode::Builtin),
|
||||
"shim" => Some(crate::DriverMode::Shim),
|
||||
_ => None,
|
||||
})
|
||||
}
|
||||
|
||||
/// Shared rule-matching walk: returns the first `extract` result from
|
||||
/// an enabled rule whose selectors match. Rules that match but yield
|
||||
/// `None` from `extract` (e.g. no target set, or no driver mode set)
|
||||
/// don't stop the walk — target rules and mode-pin rules coexist.
|
||||
fn first_match<T>(
|
||||
&self,
|
||||
mac: &str,
|
||||
arch: Option<&str>,
|
||||
extract: impl Fn(&BootRule) -> Option<T>,
|
||||
) -> Option<T> {
|
||||
let mac = normalize_mac(mac);
|
||||
let g = self.inner.read();
|
||||
for r in &g.rules {
|
||||
if !r.enabled || r.target.is_empty() {
|
||||
if !r.enabled {
|
||||
continue;
|
||||
}
|
||||
if !r.mac_prefix.is_empty() && !mac.starts_with(r.mac_prefix.as_str()) {
|
||||
@@ -151,7 +191,9 @@ impl BootRulesStore {
|
||||
_ => continue,
|
||||
}
|
||||
}
|
||||
return Some(r.target.clone());
|
||||
if let Some(v) = extract(r) {
|
||||
return Some(v);
|
||||
}
|
||||
}
|
||||
None
|
||||
}
|
||||
@@ -189,11 +231,54 @@ mod tests {
|
||||
mac_prefix: mac_prefix.into(),
|
||||
arch: arch.into(),
|
||||
target: target.into(),
|
||||
driver_mode: String::new(),
|
||||
enabled: true,
|
||||
note: String::new(),
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn driver_mode_hint_pins_known_modes_and_ignores_unknown() {
|
||||
let dir = tempdir().unwrap();
|
||||
let s = BootRulesStore::load_or_default(dir.path());
|
||||
let mut sb_rack = rule("aa:bb:cc", "", "");
|
||||
sb_rack.driver_mode = "SHIM".into(); // normalized on replace
|
||||
let mut weird = rule("11:22:33", "", "");
|
||||
weird.driver_mode = "quantum".into(); // unknown → ignored
|
||||
s.replace(BootRulesConfig {
|
||||
rules: vec![sb_rack, weird],
|
||||
webhook_url: String::new(),
|
||||
});
|
||||
assert_eq!(
|
||||
s.driver_mode_hint("aa:bb:cc:00:00:01", None),
|
||||
Some(crate::DriverMode::Shim)
|
||||
);
|
||||
assert_eq!(s.driver_mode_hint("11:22:33:00:00:01", None), None);
|
||||
assert_eq!(s.driver_mode_hint("99:99:99:00:00:01", None), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn mode_pin_rule_does_not_shadow_later_target_rule() {
|
||||
// A mode-only rule and a target rule can both apply to the same
|
||||
// client: the mode pin must not consume the target walk.
|
||||
let dir = tempdir().unwrap();
|
||||
let s = BootRulesStore::load_or_default(dir.path());
|
||||
let mut pin = rule("aa:bb", "", "");
|
||||
pin.driver_mode = "builtin".into();
|
||||
s.replace(BootRulesConfig {
|
||||
rules: vec![pin, rule("aa:bb", "", "rack-image")],
|
||||
webhook_url: String::new(),
|
||||
});
|
||||
assert_eq!(
|
||||
s.driver_mode_hint("aa:bb:00:00:00:01", None),
|
||||
Some(crate::DriverMode::Builtin)
|
||||
);
|
||||
assert_eq!(
|
||||
s.match_target("aa:bb:00:00:00:01", None).as_deref(),
|
||||
Some("rack-image")
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn empty_config_matches_nothing() {
|
||||
let dir = tempdir().unwrap();
|
||||
|
||||
Reference in New Issue
Block a user