Files
truenas-truecloud-patch/patch/patch_ui.py
T
flan 49bd775d42 Fix five quality findings from adversarial code review
sitecustomize.py — _install():
- Scope hook to middlewared service process only via sys.argv[0] check;
  previously any tool in the same venv (midclt, debug scripts) would also
  get its imports of the two target modules intercepted.
- Exec-chain a displaced sitecustomize.py: if apply.sh backed up a
  pre-existing sitecustomize.py to .pre-truecloud-patch, run it in a
  sandboxed namespace before installing our hook so any startup code
  (path additions, codec registrations) still takes effect.

sitecustomize.py — _b2_restic_config():
- Validate expected credential fields ("account", "key") before accessing
  them; raise a named KeyError listing what is missing and what is present
  so a schema change produces an attributable error at backup time rather
  than a bare KeyError with no indication this patch is involved.

sitecustomize.py — get_restic_config wrapper:
- Extend URL fix to cover all three flag forms restic accepts:
    -r <url>      (existing)
    --repo <url>  (long two-element form, now checked)
    --repo=<url>  (long single-element form, now handled)
  Without this, a restic CLI change from -r to --repo would silently make
  the fix a no-op while verify still reported the patch as OK.

patch_ui.py — find_bundle():
- Remove UnicodeDecodeError from except clause; errors="replace" in the
  open() call means the exception can never be raised, and its presence
  suggested the error parameter was not understood.
2026-06-15 03:37:26 +00:00

137 lines
4.2 KiB
Python

#!/usr/bin/env python3
"""
Patches the TrueNAS webui Angular bundle to show S3 and B2 credentials
in the TrueCloud Backup task form, instead of Storj only.
Angular's Ivy compiler inlines TypeScript string enum values as literals in
the compiled bundle, so the template binding:
[filterByProviders]="[CloudSyncProviderName.Storj]"
appears verbatim in the minified JS as:
"filterByProviders",["STORJ_IX"]
We replace that array to include S3 and B2. The file is backed up before
modification so uninstall.sh can restore it.
Safe to run multiple times — a marker string detects an already-patched file.
Exits 0 in all cases (warnings are printed to stdout and logged by apply.sh).
"""
import os
import re
import shutil
WEBUI_CANDIDATES = [
"/usr/share/truenas/webui",
"/usr/share/truenas-ui",
"/var/www/truenas",
]
# Angular's Ivy template compiler serialises the Storj-only filter as this
# exact substring in every production build we've observed.
FIND = re.compile(r'("filterByProviders",)\["STORJ_IX"\]')
REPLACE = r'\1["STORJ_IX","S3","B2"]'
# A patched file contains both "S3" and "B2" next to "STORJ_IX" in this form.
# This string is specific enough not to appear elsewhere in the bundle.
MARKER = '"STORJ_IX","S3","B2"'
def find_bundle():
"""
Search WEBUI_CANDIDATES for the JS bundle containing the filterByProviders
binding. Returns (webui_dir, path, content). webui_dir is None if no
candidate directory exists; path is None if the directory exists but the
pattern is not found in any bundle.
"""
webui = next((d for d in WEBUI_CANDIDATES if os.path.isdir(d)), None)
if webui is None:
return None, None, None
matches = []
for root, _dirs, names in os.walk(webui):
for name in sorted(names): # deterministic order
if not name.endswith(".js"):
continue
path = os.path.join(root, name)
try:
with open(path, encoding="utf-8", errors="replace") as fh:
content = fh.read()
if FIND.search(content):
matches.append((path, content))
except OSError:
continue
if not matches:
return webui, None, None
if len(matches) > 1:
# Unexpected — log all matches so the operator can investigate.
print(
f"[truecloud-patch] WARNING: filterByProviders pattern found in "
f"{len(matches)} files; patching only the first."
)
for p, _ in matches:
print(f"[truecloud-patch] {p}")
path, content = matches[0]
return webui, path, content
def main():
webui, path, content = find_bundle()
if webui is None:
print(
"[truecloud-patch] WARNING: webui directory not found; skipping UI patch.\n"
"[truecloud-patch] Searched: " + ", ".join(WEBUI_CANDIDATES)
)
return
if path is None:
print(
"[truecloud-patch] WARNING: filterByProviders pattern not found in any JS bundle.\n"
"[truecloud-patch] The TrueNAS webui may have been restructured in this version.\n"
"[truecloud-patch] File an issue at https://github.com/sudolulo/truenas-truecloud-patch\n"
f"[truecloud-patch] TrueNAS version info: {_tnversion()}"
)
return
if MARKER in content:
print(f"[truecloud-patch] UI already patched: {path}")
return
backup = path + ".pre-truecloud-patch"
if not os.path.exists(backup):
shutil.copy2(path, backup)
patched, count = FIND.subn(REPLACE, content)
tmp = path + ".tmp"
try:
with open(tmp, "w", encoding="utf-8") as fh:
fh.write(patched)
os.replace(tmp, path)
except OSError as exc:
print(f"[truecloud-patch] ERROR: Could not write {path}: {exc}")
try:
os.unlink(tmp)
except OSError:
pass
return
print(f"[truecloud-patch] UI bundle patched ({count} replacement(s)): {path}")
def _tnversion():
try:
with open("/etc/version") as fh:
return fh.read().strip()
except OSError:
return "unknown"
if __name__ == "__main__":
main()