#!/usr/bin/env bash # Verify the immutable v46 network surface is unchanged after the plugin # preview install. Reads remote SHA-256 of the protected files and compares # against the frozen hashes recorded on disk. Strictly read-only. set -euo pipefail ROUTER="${ROUTER:-root@192.168.1.2}" HASH_FILE="${HASH_FILE:?usage: verify_immutable.sh /path/to/hashes.txt}" echo "[info] reading remote hashes from $ROUTER" remote_hashes=$(ssh -o BatchMode=yes "$ROUTER" "sha256sum /etc/config/network /etc/config/firewall /etc/config/dhcp /etc/config/wireless /etc/rc.local /etc/hotplug.d/iface/20-vxlan /etc/hotplug.d/iface/30-mss-clamp /usr/share/nftables.d/chain-pre/mangle_forward/30-mss-clamp.nft 2>/dev/null" | sort) echo "[info] comparing against $HASH_FILE" while read -r expected_hash rest; do [ -z "$expected_hash" ] && continue remote_line=$(echo "$remote_hashes" | awk -v want="$rest" '$2 == want {print}') if [ -z "$remote_line" ]; then echo "MISSING: $rest" exit 1 fi if [ "${remote_line%% *}" != "$expected_hash" ]; then echo "DRIFT: $rest" echo " expected $expected_hash" echo " got ${remote_line%% *}" exit 1 fi echo "OK: $rest" done < "$HASH_FILE" echo "[ok] all immutable files match frozen hashes"