Compare commits
No commits in common. "53f861d39d57ce986b1edeb2d458a4b3fe1b37cb" and "9ecb7e5f35359a9acaa7d1ec39a86765020996b3" have entirely different histories.
53f861d39d
...
9ecb7e5f35
@ -25,27 +25,6 @@ script_task_processor_flag="$1"
|
|||||||
# Source guard — DO NOT remove. mainLoop is an infinite loop.
|
# Source guard — DO NOT remove. mainLoop is an infinite loop.
|
||||||
[[ "$script_task_processor_flag" != "start_script" ]] && return 0 2>/dev/null
|
[[ "$script_task_processor_flag" != "start_script" ]] && return 0 2>/dev/null
|
||||||
|
|
||||||
# --- Load the privilege helpers + docker-type config ------------------------
|
|
||||||
# systemd launches this script standalone, so the de-sudo helpers
|
|
||||||
# (runFileOp/runFileWrite) and the config they key off (rooted vs rootless) are
|
|
||||||
# NOT otherwise in scope. Without them every privileged write into the
|
|
||||||
# docker-install-owned task dir fails ("command not found") and tasks loop
|
|
||||||
# forever. Load them here — these files are pure function/var defs, safe to
|
|
||||||
# source, no side effects.
|
|
||||||
LP_SCRIPTS="${install_scripts_dir:-/docker/install/scripts/}"
|
|
||||||
LP_DOCKER_CFG="/docker/configs/general/general_docker_install"
|
|
||||||
[[ -f "$LP_DOCKER_CFG" ]] && \
|
|
||||||
eval "$(grep -E '^CFG_DOCKER_INSTALL_(TYPE|USER)=' "$LP_DOCKER_CFG" | sed 's/[[:space:]]*#.*//')"
|
|
||||||
: "${sudo_user_name:=libreportal}"
|
|
||||||
: "${containers_dir:=/docker/containers/}"
|
|
||||||
: "${docker_dir:=/docker}"
|
|
||||||
for _lp_f in docker/command/run_privileged.sh \
|
|
||||||
docker/command/docker_run_install.sh \
|
|
||||||
checks/requirements/check_install_type.sh; do
|
|
||||||
[[ -f "${LP_SCRIPTS}${_lp_f}" ]] && source "${LP_SCRIPTS}${_lp_f}"
|
|
||||||
done
|
|
||||||
command -v resolveDockerInstallUser >/dev/null 2>&1 && resolveDockerInstallUser
|
|
||||||
|
|
||||||
# ============================================================================
|
# ============================================================================
|
||||||
# PATHS & CONSTANTS
|
# PATHS & CONSTANTS
|
||||||
# ============================================================================
|
# ============================================================================
|
||||||
@ -137,12 +116,6 @@ setupTaskDir() {
|
|||||||
fi
|
fi
|
||||||
runFileOp chmod 666 "$FIFO" 2>/dev/null
|
runFileOp chmod 666 "$FIFO" 2>/dev/null
|
||||||
runFileOp chmod 755 "$TASK_DIR" 2>/dev/null
|
runFileOp chmod 755 "$TASK_DIR" 2>/dev/null
|
||||||
# The processor (manager user) can't create files in the docker-install-owned
|
|
||||||
# task dir, so pre-create the lock AS the dir owner, world-writable, so the
|
|
||||||
# `exec 200>"$LOCK_FILE"` in acquireSingletonLock (run as the manager) can open
|
|
||||||
# it. Create-if-absent to keep a stable inode for flock across restarts.
|
|
||||||
[[ -e "$LOCK_FILE" ]] || runFileOp install -m 666 /dev/null "$LOCK_FILE" 2>/dev/null
|
|
||||||
runFileOp chmod 666 "$LOCK_FILE" 2>/dev/null
|
|
||||||
if [[ -n "$docker_install_user" ]]; then
|
if [[ -n "$docker_install_user" ]]; then
|
||||||
runFileOp chown -R "$docker_install_user":"$docker_install_user" "$TASK_DIR" 2>/dev/null
|
runFileOp chown -R "$docker_install_user":"$docker_install_user" "$TASK_DIR" 2>/dev/null
|
||||||
fi
|
fi
|
||||||
@ -245,14 +218,14 @@ runTask() {
|
|||||||
# Previously this used `sudo truncate` + `sudo chmod 644` which left the file
|
# Previously this used `sudo truncate` + `sudo chmod 644` which left the file
|
||||||
# root-owned and unwritable to the daemon, so the redirection failed and the
|
# root-owned and unwritable to the daemon, so the redirection failed and the
|
||||||
# task immediately exited with rc=1.
|
# task immediately exited with rc=1.
|
||||||
# TASK_DIR is owned by the docker install user, so the manager-user processor
|
local daemonUser; daemonUser=$(id -un)
|
||||||
# can't create the log there directly. Create/truncate it AS the dir owner via
|
if [[ -f "$logFile" ]]; then
|
||||||
# runFileOp and leave it world-writable for the run so the eval's
|
runFileOp chown "$daemonUser":"$daemonUser" "$logFile" 2>/dev/null
|
||||||
# `>>"$logFile"` append (which runs as the manager, NOT under sudo) succeeds.
|
runFileOp chmod 664 "$logFile" 2>/dev/null
|
||||||
# Re-owned to the dir owner when the task finishes.
|
: > "$logFile" 2>/dev/null || runFileOp truncate -s 0 "$logFile" 2>/dev/null
|
||||||
runFileOp install -m 666 /dev/null "$logFile" 2>/dev/null \
|
else
|
||||||
|| runFileOp truncate -s 0 "$logFile" 2>/dev/null
|
: > "$logFile" 2>/dev/null || runFileOp install -o "$daemonUser" -g "$daemonUser" -m 664 /dev/null "$logFile"
|
||||||
runFileOp chmod 666 "$logFile" 2>/dev/null
|
fi
|
||||||
|
|
||||||
export LIBREPORTAL_NONINTERACTIVE=1
|
export LIBREPORTAL_NONINTERACTIVE=1
|
||||||
|
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user