Fix three findings from final clean-pass audit
- apply.sh: gate sitecustomize.py install on backup success; a failed backup cp (disk full, read-only mount) previously fell through and overwrote the vendor file with no recovery path - create_task.py: handle unexpected 2xx response schema in cmd_create; bare KeyError on result['id'] is replaced with a diagnostic print - uninstall.sh: mv inside while loop had no error handling; under set -euo pipefail a failed mv aborted the script before rm -rf PATCH_DIR, leaving the system in partial-uninstall limbo
This commit is contained in:
+14
-7
@@ -85,17 +85,24 @@ if [ -z "$SITE_PKG" ]; then
|
|||||||
echo " Run: $PYTHON -c \"import site; print(site.getsitepackages())\""
|
echo " Run: $PYTHON -c \"import site; print(site.getsitepackages())\""
|
||||||
else
|
else
|
||||||
# Back up any pre-existing sitecustomize.py that isn't ours.
|
# Back up any pre-existing sitecustomize.py that isn't ours.
|
||||||
|
_can_install=true
|
||||||
if [ -f "$SITE_PKG/sitecustomize.py" ] && \
|
if [ -f "$SITE_PKG/sitecustomize.py" ] && \
|
||||||
! grep -q "truecloud-patch" "$SITE_PKG/sitecustomize.py" 2>/dev/null; then
|
! grep -q "truecloud-patch" "$SITE_PKG/sitecustomize.py" 2>/dev/null; then
|
||||||
cp "$SITE_PKG/sitecustomize.py" \
|
if cp "$SITE_PKG/sitecustomize.py" \
|
||||||
"$SITE_PKG/sitecustomize.py.pre-truecloud-patch"
|
"$SITE_PKG/sitecustomize.py.pre-truecloud-patch"; then
|
||||||
echo "OK: Backed up existing sitecustomize.py"
|
echo "OK: Backed up existing sitecustomize.py"
|
||||||
|
else
|
||||||
|
echo "WARNING: Could not back up existing sitecustomize.py; skipping install to avoid data loss."
|
||||||
|
_can_install=false
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if cp "$PATCH_DIR/sitecustomize.py" "$SITE_PKG/sitecustomize.py" 2>/dev/null; then
|
if $_can_install; then
|
||||||
echo "OK: Installed sitecustomize.py → $SITE_PKG/sitecustomize.py"
|
if cp "$PATCH_DIR/sitecustomize.py" "$SITE_PKG/sitecustomize.py" 2>/dev/null; then
|
||||||
else
|
echo "OK: Installed sitecustomize.py → $SITE_PKG/sitecustomize.py"
|
||||||
echo "WARNING: Failed to write $SITE_PKG/sitecustomize.py (permission error?)"
|
else
|
||||||
|
echo "WARNING: Failed to write $SITE_PKG/sitecustomize.py (permission error?)"
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
@@ -179,7 +179,10 @@ def cmd_create(client, args):
|
|||||||
}
|
}
|
||||||
|
|
||||||
result = client("POST", "/cloud_backup", body)
|
result = client("POST", "/cloud_backup", body)
|
||||||
print(f"Created task id={result['id']} name={result['description']!r}")
|
try:
|
||||||
|
print(f"Created task id={result['id']} name={result['description']!r}")
|
||||||
|
except (KeyError, TypeError):
|
||||||
|
print(f"Task created but response schema was unexpected: {result}")
|
||||||
|
|
||||||
|
|
||||||
# ── CLI ───────────────────────────────────────────────────────────────────────
|
# ── CLI ───────────────────────────────────────────────────────────────────────
|
||||||
|
|||||||
+6
-3
@@ -104,9 +104,12 @@ echo "Restoring UI bundle backup ..."
|
|||||||
RESTORED=0
|
RESTORED=0
|
||||||
while IFS= read -r backup; do
|
while IFS= read -r backup; do
|
||||||
original="${backup%.pre-truecloud-patch}"
|
original="${backup%.pre-truecloud-patch}"
|
||||||
mv "$backup" "$original"
|
if mv "$backup" "$original"; then
|
||||||
echo " Restored: $original"
|
echo " Restored: $original"
|
||||||
RESTORED=1
|
RESTORED=1
|
||||||
|
else
|
||||||
|
echo " WARNING: Could not restore $original — backup left at $backup"
|
||||||
|
fi
|
||||||
# Keep these paths in sync with WEBUI_CANDIDATES in patch/patch_ui.py
|
# Keep these paths in sync with WEBUI_CANDIDATES in patch/patch_ui.py
|
||||||
done < <(find /usr/share/truenas /usr/share/truenas-ui /var/www/truenas \
|
done < <(find /usr/share/truenas /usr/share/truenas-ui /var/www/truenas \
|
||||||
-name "*.js.pre-truecloud-patch" 2>/dev/null)
|
-name "*.js.pre-truecloud-patch" 2>/dev/null)
|
||||||
|
|||||||
Reference in New Issue
Block a user