Fix four audit findings
- patch/apply.sh: replace sed with Python+env-var for PATCH_DIR
substitution into sitecustomize.py; sed's & and | metacharacters
silently corrupt or truncate the output for paths containing those
chars; Python str.replace has no metacharacter issues; also write to
a tmp file and mv atomically so a failed substitution never leaves
an empty sitecustomize.py at the destination
- recover.sh: fix re-enable hint from $PATCH_DIR/apply.sh to
$PATCH_DIR/patch/apply.sh (apply.sh moved into patch/ subdirectory)
- install.sh + uninstall.sh: match PREINIT hook on comment field
("TrueCloud provider patch (S3/B2)") instead of exact script path;
exact-path match breaks when the repo is moved after install —
uninstall leaves the stale hook registered (fires on every boot),
and reinstall creates a duplicate entry; install.sh now also updates
the script path on re-run so a moved repo self-corrects
This commit is contained in:
+3
-3
@@ -64,15 +64,15 @@ EXISTING_ID=$(midclt call initshutdownscript.query '[]' | \
|
||||
python3 -c "
|
||||
import sys, json
|
||||
for s in json.load(sys.stdin):
|
||||
if s.get('script') == '$PATCH_DIR/patch/apply.sh':
|
||||
if s.get('comment') == 'TrueCloud provider patch (S3/B2)':
|
||||
print(s['id'])
|
||||
break
|
||||
" 2>/dev/null || true)
|
||||
|
||||
if [ -n "$EXISTING_ID" ]; then
|
||||
echo "Already registered (id=$EXISTING_ID). Ensuring it is enabled ..."
|
||||
echo "Already registered (id=$EXISTING_ID). Updating path and enabling ..."
|
||||
midclt call initshutdownscript.update "$EXISTING_ID" \
|
||||
'{"enabled": true}' > /dev/null
|
||||
"{\"enabled\": true, \"script\": \"$PATCH_DIR/patch/apply.sh\"}" > /dev/null
|
||||
else
|
||||
midclt call initshutdownscript.create \
|
||||
"{\"type\":\"SCRIPT\",\"script\":\"$PATCH_DIR/patch/apply.sh\",\"when\":\"PREINIT\",\"enabled\":true,\"comment\":\"TrueCloud provider patch (S3/B2)\"}" \
|
||||
|
||||
Reference in New Issue
Block a user