Fix four audit findings

- patch/apply.sh: replace sed with Python+env-var for PATCH_DIR
  substitution into sitecustomize.py; sed's & and | metacharacters
  silently corrupt or truncate the output for paths containing those
  chars; Python str.replace has no metacharacter issues; also write to
  a tmp file and mv atomically so a failed substitution never leaves
  an empty sitecustomize.py at the destination
- recover.sh: fix re-enable hint from $PATCH_DIR/apply.sh to
  $PATCH_DIR/patch/apply.sh (apply.sh moved into patch/ subdirectory)
- install.sh + uninstall.sh: match PREINIT hook on comment field
  ("TrueCloud provider patch (S3/B2)") instead of exact script path;
  exact-path match breaks when the repo is moved after install —
  uninstall leaves the stale hook registered (fires on every boot),
  and reinstall creates a duplicate entry; install.sh now also updates
  the script path on re-run so a moved repo self-corrects
This commit is contained in:
2026-06-15 17:36:58 +00:00
parent 70e84038d6
commit 6a8ed7fa67
4 changed files with 18 additions and 8 deletions
+3 -3
View File
@@ -64,15 +64,15 @@ EXISTING_ID=$(midclt call initshutdownscript.query '[]' | \
python3 -c " python3 -c "
import sys, json import sys, json
for s in json.load(sys.stdin): for s in json.load(sys.stdin):
if s.get('script') == '$PATCH_DIR/patch/apply.sh': if s.get('comment') == 'TrueCloud provider patch (S3/B2)':
print(s['id']) print(s['id'])
break break
" 2>/dev/null || true) " 2>/dev/null || true)
if [ -n "$EXISTING_ID" ]; then if [ -n "$EXISTING_ID" ]; then
echo "Already registered (id=$EXISTING_ID). Ensuring it is enabled ..." echo "Already registered (id=$EXISTING_ID). Updating path and enabling ..."
midclt call initshutdownscript.update "$EXISTING_ID" \ midclt call initshutdownscript.update "$EXISTING_ID" \
'{"enabled": true}' > /dev/null "{\"enabled\": true, \"script\": \"$PATCH_DIR/patch/apply.sh\"}" > /dev/null
else else
midclt call initshutdownscript.create \ midclt call initshutdownscript.create \
"{\"type\":\"SCRIPT\",\"script\":\"$PATCH_DIR/patch/apply.sh\",\"when\":\"PREINIT\",\"enabled\":true,\"comment\":\"TrueCloud provider patch (S3/B2)\"}" \ "{\"type\":\"SCRIPT\",\"script\":\"$PATCH_DIR/patch/apply.sh\",\"when\":\"PREINIT\",\"enabled\":true,\"comment\":\"TrueCloud provider patch (S3/B2)\"}" \
+13 -3
View File
@@ -100,11 +100,21 @@ else
if [ "$_can_install" = true ]; then if [ "$_can_install" = true ]; then
# Substitute PATCH_DIR into the source so sitecustomize.py knows where # Substitute PATCH_DIR into the source so sitecustomize.py knows where
# to write hook_status.json and check the kill switch at runtime. # to write hook_status.json and check the kill switch at runtime.
if sed "s|/data/truecloud-patch|$PATCH_DIR|g" \ # Pass PATCH_DIR via env var so arbitrary path characters don't break
"$PATCH_DIR/patch/sitecustomize.py" \ # the substitution (sed metacharacters & and | are unsafe in shell-
> "$SITE_PKG/sitecustomize.py"; then # interpolated replacement strings). Write to a temp file first so a
# failed substitution never truncates the existing sitecustomize.py.
_sc_tmp="$SITE_PKG/sitecustomize.py.truecloud-tmp"
if TRUECLOUD_PATCH_DIR="$PATCH_DIR" \
"$PYTHON" -c "
import os, sys
d = os.environ['TRUECLOUD_PATCH_DIR']
with open(d + '/patch/sitecustomize.py', encoding='utf-8') as fh:
sys.stdout.write(fh.read().replace('/data/truecloud-patch', d))
" > "$_sc_tmp" && mv "$_sc_tmp" "$SITE_PKG/sitecustomize.py"; then
echo "OK: Installed sitecustomize.py → $SITE_PKG/sitecustomize.py" echo "OK: Installed sitecustomize.py → $SITE_PKG/sitecustomize.py"
else else
rm -f "$_sc_tmp"
echo "WARNING: Failed to write $SITE_PKG/sitecustomize.py (permission error?)" echo "WARNING: Failed to write $SITE_PKG/sitecustomize.py (permission error?)"
fi fi
fi fi
+1 -1
View File
@@ -45,4 +45,4 @@ fi
echo "" echo ""
echo "To re-enable the patch once you have investigated:" echo "To re-enable the patch once you have investigated:"
echo " rm $PATCH_DIR/disabled" echo " rm $PATCH_DIR/disabled"
echo " bash $PATCH_DIR/apply.sh" echo " bash $PATCH_DIR/patch/apply.sh"
+1 -1
View File
@@ -26,7 +26,7 @@ IDS=$(midclt call initshutdownscript.query '[]' | \
python3 -c " python3 -c "
import sys, json import sys, json
for s in json.load(sys.stdin): for s in json.load(sys.stdin):
if s.get('script') == '$PATCH_DIR/patch/apply.sh': if s.get('comment') == 'TrueCloud provider patch (S3/B2)':
print(s['id']) print(s['id'])
" 2>/dev/null || true) " 2>/dev/null || true)