Files
felhom.eu/documentation/audits/gate-rollout-2026-09-29/D/d_claper.py
T

22 lines
1.3 KiB
Python

# R-713 live: claper installed with a household-typed password holding " and #{ ; the box's after_install must set it
# (base64 into the Elixir code) — then the default fails and the typed one works. The password stays in memory/stdin.
import json, os, secrets, subprocess, sys, time
sys.path.insert(0, '.')
import ro
from ro import w
w.login()
pw = 'Fam"ily#{x}-' + secrets.token_hex(6)
v = w.deploy_values("claper", "r-claper"); v["ADMIN_PASSWORD"] = pw
code, d = w.ctl("POST", "/api/stacks/claper/deploy", {"values": v, "kept_data": "fresh"})
w.say("claper deploy with a typed password holding a quote and #{ ->", code)
t0 = time.time()
while time.time() - t0 < 900:
rec = (w.stack("claper").get("app_config") or {}).get("after_install")
if rec:
w.say(f"claper after_install record after {time.time()-t0:.0f}s: ok={rec.get('ok')} detail={str(rec.get('detail'))[:90]!r}"); break
time.sleep(10)
script = open("claper_login.sh").read()
subprocess.run(["ssh", "hp", "cat > /root/cl.sh && pct push 9202 /root/cl.sh /root/cl.sh && rm /root/cl.sh"], input=script, text=True, check=True, capture_output=True)
r = subprocess.run(["ssh", "hp", "pct exec 9202 -- bash /root/cl.sh; pct exec 9202 -- rm -f /root/cl.sh"], input=pw + "\n", text=True, capture_output=True, timeout=300)
print(r.stdout.replace(pw, "<typed>"), end="")