Files
felhom.eu/documentation/audits/kernel-spike-2026-10-07/tools/spike-watchdog-setup.sh
T

15 lines
1.1 KiB
Bash

#!/bin/bash
# Candidate 3 (R-836): a hardware watchdog armed by systemd during the reboot (RebootWatchdogSec) and petted at runtime
# (RuntimeWatchdogSec). The driver is loaded by name at every boot (Proxmox blacklists hardware watchdog drivers for its
# HA softdog); a udev link gives it a stable name. Usage: spike-watchdog-setup.sh <module> "<sysfs identity>"
# Reversible: spike-watchdog-undo.sh
set -euo pipefail
MOD=$1 ID=$2
echo "$MOD" > /etc/modules-load.d/felhom-spike-watchdog.conf
echo "KERNEL==\"watchdog[0-9]*\", ATTR{identity}==\"$ID\", SYMLINK+=\"felhom-hwwd\"" > /etc/udev/rules.d/70-felhom-spike-watchdog.rules
mkdir -p /etc/systemd/system.conf.d
printf '[Manager]\nWatchdogDevice=/dev/felhom-hwwd\nRuntimeWatchdogSec=30s\nRebootWatchdogSec=90s\n' > /etc/systemd/system.conf.d/felhom-spike-watchdog.conf
modprobe "$MOD"; udevadm control --reload; udevadm trigger --subsystem-match=watchdog; udevadm settle
ls -la /dev/felhom-hwwd; systemctl daemon-reexec; sleep 2
for w in /sys/class/watchdog/*; do echo "$w $(cat $w/identity) timeout=$(cat $w/timeout) state=$(cat $w/state)"; done