#!/bin/bash #=============================================================================== # felhom-mkfs-guarded — the ONLY mkfs path the felhom-agent sudoers permits (Impl-1 Part B, # SPIKE-drive-enrollment-2026-07-01 §SQ3). Defense-in-depth BELOW the agent: even a buggy or # compromised agent cannot mkfs a catastrophic target through this — it re-checks, as root, the # cheap catastrophic cases (OS/system disk, LVM physical volume, a foreign mount) and refuses. # # The agent's full unclaimed-disk filter (internal/storage/claim.go) is the PRIMARY guard; this # wrapper is a deliberately minimal, auditable second gate. It is NOT the place for the full filter. # # Usage: felhom-mkfs-guarded #=============================================================================== set -euo pipefail die() { echo "felhom-mkfs-guarded: REFUSED: $*" >&2; exit 1; } dev="${1:-}"; fstype="${2:-}" [[ -n "$dev" && -n "$fstype" ]] || die "usage: felhom-mkfs-guarded " # The device must be a REAL block-device node under /dev — no symlink (e.g. /dev/disk/by-*), no traversal. [[ "$dev" == /dev/* ]] || die "device must be under /dev ($dev)" [[ "$dev" != *..* ]] || die "path traversal ($dev)" [[ -b "$dev" ]] || die "not a block device ($dev)" [[ ! -L "$dev" ]] || die "device must be a real node, not a symlink ($dev)" # Whole-disk of the target (a partition's parent, else the disk itself). pk="$(lsblk -ndo PKNAME "$dev" 2>/dev/null || true)" whole="$dev"; [[ -n "$pk" ]] && whole="/dev/$pk" # 1) OS/system disk — does the target's whole-disk back /, /boot or /boot/efi? while read -r src mnt _rest; do case "$mnt" in /|/boot|/boot/efi) spk="$(lsblk -ndo PKNAME "$src" 2>/dev/null || true)" swhole="$src"; [[ -n "$spk" ]] && swhole="/dev/$spk" [[ "$swhole" == "$whole" || "$src" == "$dev" || "$src" == "$whole" ]] && die "system/OS disk ($dev backs $mnt)" ;; esac done < /proc/mounts # 2) LVM physical volume anywhere on the target disk or its partitions. if command -v pvs >/dev/null 2>&1; then while read -r pv; do pv="${pv//[[:space:]]/}"; [[ -z "$pv" ]] && continue pvpk="$(lsblk -ndo PKNAME "$pv" 2>/dev/null || true)" pvwhole="$pv"; [[ -n "$pvpk" ]] && pvwhole="/dev/$pvpk" [[ "$pvwhole" == "$whole" ]] && die "device holds an LVM physical volume ($pv)" done < <(pvs --noheadings -o pv_name 2>/dev/null || true) fi # 3) mounted OUTSIDE Felhom's own drive area = a live foreign filesystem → catastrophic. Mounts under # /mnt/felhom-drives are our own drives (the agent detaches before a re-init) → allowed. while read -r mp; do [[ -z "$mp" ]] && continue case "$mp" in /mnt/felhom-drives|/mnt/felhom-drives/*) : ;; *) die "device (or a partition) is mounted at $mp ($dev)" ;; esac done < <(lsblk -nro MOUNTPOINT "$whole" 2>/dev/null || true) # Passed the catastrophic checks → format. exec so the mkfs exit status is the wrapper's. case "$fstype" in ext4) exec /usr/sbin/mkfs.ext4 -F "$dev" ;; xfs) exec /usr/sbin/mkfs.xfs -f "$dev" ;; *) die "unsupported fstype ($fstype)" ;; esac