c03702707b
The binary records only the commit it was built from -- no dirty-tree flag. Cargo will not re-run a build script because another crate's source changed, so a compiled-in 'clean' claim can be stale and is not a safeguard; that was verified on the Blaze host. scripts/verify-build-identity.sh establishes both facts at LAUNCH, where they cannot go stale: the stamped commit equals HEAD, and the migration crates are clean. It REFUSES rather than warns, because for a migration gate a warning on stderr is something to scroll past. --identity prints the stamp without valid configuration. The launcher must be able to establish which commit a binary came from BEFORE deciding whether to run it; requiring a correct environment first would invert the check. redirector.sh mirrors sidecar.sh: refuses to start with an orphan present or the port busy, matches the resolved executable rather than the command line (pgrep -f matches any shell mentioning the name), and stop PROVES the process is gone and the port free. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
43 lines
1.7 KiB
Rust
43 lines
1.7 KiB
Rust
//! Entry point for the FIFA 17 redirector host.
|
|
|
|
use openfut_redirector_host::{serve, RedirectorConfig};
|
|
|
|
fn main() {
|
|
// Identity must be readable WITHOUT valid configuration: the launcher has
|
|
// to verify which commit a binary came from before deciding whether to run
|
|
// it at all, and refusing to reveal that until the environment is right
|
|
// would invert the check.
|
|
if std::env::args().any(|a| a == "--identity") {
|
|
println!("{}", openfut_redirector_host::identity());
|
|
return;
|
|
}
|
|
|
|
let cfg = match RedirectorConfig::from_env() {
|
|
Ok(c) => c,
|
|
Err(e) => {
|
|
eprintln!("openfut-redirector-host: {e}\n");
|
|
eprintln!("Required:");
|
|
eprintln!(
|
|
" OPENFUT_ADVERTISE address the game machine reaches this host at"
|
|
);
|
|
eprintln!(
|
|
" OPENFUT_REDIRECTOR_HOST_PORT listen port (no default: runs beside Python)"
|
|
);
|
|
eprintln!(
|
|
" OPENFUT_REDIRECTOR_CERT RSA certificate (reuse the oracle's for A/B)"
|
|
);
|
|
eprintln!(" OPENFUT_REDIRECTOR_KEY matching private key");
|
|
eprintln!("Optional:");
|
|
eprintln!(" OPENFUT_REDIRECTOR_HOST_BIND listener bind (defaults to OPENFUT_BIND)");
|
|
eprintln!(" OPENFUT_BLAZE_ADVERTISED_PORT Blaze port put in the redirect");
|
|
eprintln!(" OPENFUT_REDIRECTOR_CIPHERS override the cipher list");
|
|
eprintln!(" OPENFUT_REDIRECTOR_SECURITY_LEVEL only with evidence it is needed");
|
|
std::process::exit(2);
|
|
}
|
|
};
|
|
if let Err(e) = serve(cfg) {
|
|
eprintln!("openfut-redirector-host: fatal: {e}");
|
|
std::process::exit(1);
|
|
}
|
|
}
|