LibrePortal/scripts/function/file/create_touch.sh
librelad e4872ab511 refactor(paths): single source of truth for a relocatable, split layout (phase 1)
Introduce scripts/source/paths.sh as the canonical path resolver for three
independently-relocatable roots:
  LP_SYSTEM_DIR      manager-owned control plane (configs/logs/install/db/ssl/ssh/migrate)
  LP_CONTAINERS_DIR  container-user-owned live app data
  LP_BACKUPS_DIR     container-user-owned backup repos (own mount-able)

Roots come from the environment when set (install bakes them; CLI/app inherit
from init.sh), else default to /libreportal-*. A transitional compat default
keeps EXISTING installs (legacy single /docker tree, by config marker) on /docker
until a deliberate reinstall, so deploying this never strands a running box.

- init.sh derives the same vars inline (self-contained for the bare /root/init.sh
  reinstall case); paths.sh mirrors it for the standalone task/check processors,
  which now self-locate their scripts dir and source it.
- Replace functional /docker literals with the derived vars across runtime,
  install, backup, crontab, crowdsec/restic, headscale, and reinstall paths;
  clean the inert '== /docker/containers/*' guard fallbacks to the variable form.
- backend: CONTAINERS_DIR now from LP_CONTAINERS_DIR (compose env, filled at
  generation via a new CONTAINERS_DIR_TAG), legacy-safe default for un-recreated
  containers.
- backup default path falls back to the backups root; exclude paths.sh from the
  sourced-file arrays (bootstrap file, sourced explicitly).

The CLI-wrapper heredoc + root helpers still reference /docker; those get baked
in phase 3. No layout/ownership change yet (phase 2).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Signed-off-by: librelad <librelad@digitalangels.vip>
2026-05-25 15:09:39 +01:00

37 lines
1.5 KiB
Bash
Executable File

#!/bin/bash
# Create an empty file with the correct owner FOR ITS LOCATION.
# under /docker/containers/<app>/ -> app data, owned by the docker install
# user -> create via runFileOp.
# anywhere else -> manager control plane -> runInstallOp
# (the current/manager user).
# Creating the file directly as the right owner avoids chown-to-another-user,
# which needs real root and isn't available to the unprivileged runtime.
# $2 (user_name) is kept for call-site compatibility but is now advisory — the
# path decides the owner, so a stale hint (e.g. passing the manager user for a
# file that lives under containers/) no longer lands the file with the wrong
# owner. Parent dirs are created with the same owner.
createTouch()
{
local file="$1"
local user_name="$2" # advisory; location determines the real owner
local silent_flag="$3"
local clean_file=$(echo "$file" | sed 's#//*#/#g')
local file_name=$(basename "$clean_file")
local file_dir=$(dirname "$clean_file")
local op="runInstallOp"
if [[ "$clean_file" == "$containers_dir"* || "$clean_file" == "${LP_CONTAINERS_DIR:-/libreportal-containers}"/* ]]; then
op="runFileOp"
fi
if [ "$silent_flag" == "silent" ]; then
$op mkdir -p "$file_dir" 2>/dev/null
$op touch "$clean_file"
else
local result=$($op mkdir -p "$file_dir")
local result=$($op touch "$clean_file")
checkSuccess "Touching $file_name"
fi
}