LibrePortal/variables.sh
librelad 48cb5d9380 fix(backup): name preserved env vars instead of relying on sudo -E
sudo-rs — the default sudo from Ubuntu 25.10, so on 26.04 — does not
implement bare -E. It does not reject it either: it warns to stderr
("preserving the entire environment is not supported, '-E' is ignored")
and runs the command with the environment DROPPED, leaving the exit
status untouched. Callers capture stderr, so the warning is invisible and
the backup engines simply never receive RESTIC_PASSWORD / BORG_PASSPHRASE
/ KOPIA_PASSWORD and cannot open the repository.

Name the nine vars explicitly via --preserve-env=<list>, which sudo-rs
and classic sudo (>=1.8.21, so Debian 10's 1.8.27) both honour, so this
needs no version gate. The list is cross-checked against every
RESTIC_/BORG_/KOPIA_ var the engine env scripts export.

The list lives in variables.sh with a literal fallback in runBackupOp,
because init.sh sources run_privileged.sh directly during install without
ever loading variables.sh — an unguarded empty list would silently
reproduce the same dropped-credential bug.

restoreFirstRunDiscover now goes through runBackupOp rather than issuing
its own sudo. It was the only backup-engine call bypassing that funnel,
which is why it missed this fix by construction; routing it back also
gives it the -H that keeps restic's cache under the backup user's HOME.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-01 11:15:29 +01:00

72 lines
2.5 KiB
Bash
Executable File

#!/bin/bash
trap exitScript SIGINT
# Directories are contained in init.sh
# Define text colors
GREEN='\033[0;32m'
RED='\033[0;31m'
YELLOW='\033[0;33m'
BLUE='\033[1;34m'
PINK='\033[0;35m'
CYAN='\033[0;36m'
BOLD='\033[1m'
DIM='\033[2m'
NC='\033[0m' # No Color
# Date/Time
backupDate=$(date +'%F')
backupFolder="backup_$(date +"%Y%m%d%H%M%S")"
current_date=$(date +%Y-%m-%d)
current_time=$(date +%H:%M:%S)
# Domain/Network
# Try to get public IP, fallback to local IP if all fail
if command -v dig >/dev/null 2>&1; then
public_ip_v4=$(dig +short myip.opendns.com @resolver1.opendns.com 2>/dev/null)
fi
# Fallback to local IP if dig failed or returned empty
if [[ -z "$public_ip_v4" ]]; then
public_ip_v4=$(hostname -I | awk '{print $1}' 2>/dev/null)
fi
# Final fallback to localhost
if [[ -z "$public_ip_v4" ]]; then
public_ip_v4="localhost"
fi
server_nic="$(ip -4 route ls | grep default | grep -Po '(?<=dev )(\S+)' | head -1)"
default_subnet="10.100.0"
# Files
docker_rooted_socket="/var/run/docker.sock"
swap_file=/swapfile
# Rootless sysctl settings + the "rootless configured" marker. MUST live under
# /etc/sysctl.d/ — `sysctl --system` only reads there (+ /etc/sysctl.conf), NOT
# the old non-standard /etc/sysctl/ path, so settings written elsewhere never
# persist across reboot.
sysctl="/etc/sysctl.d/99-libreportal-rootless.conf"
# Rootless Docker's installer aborts outright when the legacy ip_tables modules
# aren't loaded. Ubuntu 24.04/26.04 don't autoload them on a fresh box, so we
# both modprobe them now and persist them here for subsequent boots.
modules_load="/etc/modules-load.d/libreportal-rootless.conf"
# Env vars that must survive the privilege drop into $docker_install_user for the
# backup engines to open their repository (repo URI + passphrase + ssh transport).
# Named explicitly rather than relying on `sudo -E`: sudo-rs, the default on
# Ubuntu 25.10+ (incl. 26.04), does not implement bare -E — it warns and runs the
# command with the environment dropped. Keep in sync with the fallback list in
# scripts/docker/command/run_privileged.sh (init.sh sources that file directly,
# without this one).
backup_env_preserve="BORG_PASSPHRASE,BORG_REPO,BORG_RSH,KOPIA_CHECK_FOR_UPDATES,KOPIA_CONFIG_PATH,KOPIA_PASSWORD,RESTIC_PASSWORD,RESTIC_REPOSITORY,RESTIC_SFTP_COMMAND"
docker_log_file=libreportal.log
backup_log_file=backup.log
db_file=database.db
migrate_file=migrate.txt
run_file=run.txt
# Configs
update_done=false
config_file_wireguard=config_wireguard
# Menu
menu_number=0