Serialize enrollment install with enrolling.lock
Concurrent enroll-url launches could both pass the enrollment
marker check and run overlapping elevated installs, racing on
LoadOrExchangeAPIKey and overwriting agent.key.
Add an exclusive flock on {configDir}/enrolling.lock for the
full install path and re-check IsEnrolled under that lock so
only one install exchanges a token and configures the device.
Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
@@ -29,7 +29,7 @@ func DefaultConfigDir() string {
|
||||
}
|
||||
|
||||
// DefaultEnrollmentRunDir returns the runtime directory for the public
|
||||
// enrollment marker on non-Windows hosts.
|
||||
// enrollment marker and enrolling.lock on non-Windows hosts.
|
||||
func DefaultEnrollmentRunDir() string {
|
||||
return "/var/run/probo-agent"
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user