From 756b8f6004b60427d9878a9c0b3d80d560b7f81b Mon Sep 17 00:00:00 2001 From: seaHi Date: Fri, 9 Oct 2026 15:05:12 +0800 Subject: [PATCH] =?UTF-8?q?fix:=20=E4=BC=98=E5=8C=96=20firewalld=20?= =?UTF-8?q?=E6=A3=80=E6=9F=A5=E9=80=BB=E8=BE=91=E4=BB=A5=E5=85=BC=E5=AE=B9?= =?UTF-8?q?=20CentOS=207=20=E7=9A=84=E7=8A=B6=E6=80=81=E8=BF=94=E5=9B=9E?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- 3-5-compute.sh | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/3-5-compute.sh b/3-5-compute.sh index 91dcb7c..f0787f8 100755 --- a/3-5-compute.sh +++ b/3-5-compute.sh @@ -138,7 +138,17 @@ if [ -n "${CHECK_COMPUTE_IP:-}" ] && ! valid_ipv4 "$CHECK_COMPUTE_IP"; then erro case "$REPO_BASE" in http://*|https://*) ;; *) error '软件源根 URL 必须使用 http(s)。未评分。'; exit 2;; esac section '安全设置(8分)' '节点环境准备 / 二、基础安全设置' -firewall_stopped() { [ "$(timeout 10 systemctl is-active firewalld 2>/dev/null)" = inactive ]; } +firewall_stopped() { + local properties + # CentOS 7 上 is-active 可能返回 unknown;直接查询服务属性确认状态。 + # 不使用 --value,兼容旧版 systemctl;服务不存在或查询失败不能算通过。 + properties=$(timeout 10 systemctl show firewalld.service -p LoadState -p ActiveState 2>/dev/null) || return 1 + printf '%s\n' "$properties" | awk -F= ' + $1=="LoadState" {load=$2; loads++} + $1=="ActiveState" {active=$2; actives++} + END {exit !(loads==1 && actives==1 && + (load=="loaded" || load=="masked") && active=="inactive")}' +} firewall_disabled() { local state state=$(timeout 10 systemctl is-enabled firewalld 2>/dev/null)