fix: 优化 firewalld 检查逻辑以兼容 CentOS 7 的状态返回
This commit is contained in:
1 parent
b2bc382711
commit
756b8f6004
1 file changed
+11
-1
+11
-1
@@ -138,7 +138,17 @@ if [ -n "${CHECK_COMPUTE_IP:-}" ] && ! valid_ipv4 "$CHECK_COMPUTE_IP"; then erro
|
|||||||
case "$REPO_BASE" in http://*|https://*) ;; *) error '软件源根 URL 必须使用 http(s)。未评分。'; exit 2;; esac
|
case "$REPO_BASE" in http://*|https://*) ;; *) error '软件源根 URL 必须使用 http(s)。未评分。'; exit 2;; esac
|
||||||
|
|
||||||
section '安全设置(8分)' '节点环境准备 / 二、基础安全设置'
|
section '安全设置(8分)' '节点环境准备 / 二、基础安全设置'
|
||||||
firewall_stopped() { [ "$(timeout 10 systemctl is-active firewalld 2>/dev/null)" = inactive ]; }
|
firewall_stopped() {
|
||||||
|
local properties
|
||||||
|
# CentOS 7 上 is-active 可能返回 unknown;直接查询服务属性确认状态。
|
||||||
|
# 不使用 --value,兼容旧版 systemctl;服务不存在或查询失败不能算通过。
|
||||||
|
properties=$(timeout 10 systemctl show firewalld.service -p LoadState -p ActiveState 2>/dev/null) || return 1
|
||||||
|
printf '%s\n' "$properties" | awk -F= '
|
||||||
|
$1=="LoadState" {load=$2; loads++}
|
||||||
|
$1=="ActiveState" {active=$2; actives++}
|
||||||
|
END {exit !(loads==1 && actives==1 &&
|
||||||
|
(load=="loaded" || load=="masked") && active=="inactive")}'
|
||||||
|
}
|
||||||
firewall_disabled() {
|
firewall_disabled() {
|
||||||
local state
|
local state
|
||||||
state=$(timeout 10 systemctl is-enabled firewalld 2>/dev/null)
|
state=$(timeout 10 systemctl is-enabled firewalld 2>/dev/null)
|
||||||
|
|||||||
Reference in new issue
Block a user