Security -------- create_task.py shelled out to `midclt call cloud_backup.create '<json>'`, and that JSON carries the restic repository password -- so it sat in the subprocess's argv, which is world-readable via ps, for the duration of the call. That password is the encryption key for the entire cloud backup repository. It now talks to the middleware through truenas_api_client, the library that backs midclt itself, so the password never leaves this process's memory. Verified on a live box: list-tasks and list-credentials work through the new transport. --password is also no longer required, because passing a secret as a CLI argument writes it to shell history permanently. --password-stdin reads it from stdin, and with neither flag the tool prompts via getpass. --password still works but warns. Fixed ----- uninstall.sh could leave every patch installed. It reverted by unmounting the overlay -- but apply.sh only mounts one when the target directory is read-only. On a writable /usr it patches the real files in place, and uninstall would remove the boot hook, report success, and leave the patch applied. It now strips the appended blocks from the middleware files explicitly. This also covers the case where the overlay unmount fails. create_task.py's __version__ had been stuck at 0.2.0 through three releases. The version-drift check added in v0.3.1 only looked at VERSION= in shell scripts, so it missed the one file that actually shows a version to users (--version). The check now covers __version__ too -- and caught this immediately. 118 tests, ruff and shellcheck clean.
86 lines
3.0 KiB
Bash
Executable File
86 lines
3.0 KiB
Bash
Executable File
#!/bin/bash
|
|
# recover.sh — emergency recovery if middlewared won't start after installing truecloud-patch.
|
|
#
|
|
# Run this from the TrueNAS shell (local console, SSH, or debug shell):
|
|
#
|
|
# bash /mnt/tank/truenas-truecloud-patch/recover.sh
|
|
#
|
|
# What it does:
|
|
# 1. Creates a "disabled" file in the repo root — apply.sh checks for this
|
|
# file at boot and skips all patching, so the next boot is always clean.
|
|
# 2. Unmounts any active truecloud overlays so the original /usr files are
|
|
# visible immediately (no reboot required).
|
|
# 3. Restarts middlewared against the unpatched files.
|
|
#
|
|
# To re-enable the patch after investigating:
|
|
# rm /mnt/tank/truenas-truecloud-patch/disabled
|
|
# bash /mnt/tank/truenas-truecloud-patch/patch/apply.sh
|
|
# systemctl restart middlewared
|
|
|
|
VERSION="0.3.3"
|
|
|
|
PATCH_DIR="$(cd "$(dirname "$0")" && pwd)"
|
|
|
|
|
|
echo "=== TrueNAS TrueCloud Provider Patch v${VERSION} — Recover ==="
|
|
echo ""
|
|
|
|
if [ "$(id -u)" -ne 0 ]; then
|
|
echo "ERROR: must be run as root." >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [ ! -d "$PATCH_DIR" ]; then
|
|
echo "ERROR: $PATCH_DIR not found — truecloud-patch may not be installed." >&2
|
|
exit 1
|
|
fi
|
|
|
|
touch "$PATCH_DIR/disabled"
|
|
echo "Kill switch set: $PATCH_DIR/disabled created."
|
|
|
|
echo "Unmounting truecloud overlays ..."
|
|
_any=0
|
|
for _tag in mw ui; do
|
|
if mount | grep -qF "truecloud-${_tag} on "; then
|
|
_mnt=$(mount | grep "truecloud-${_tag} on " | awk '{print $3}' | head -1)
|
|
if umount "$_mnt" 2>/dev/null; then
|
|
echo " Unmounted: $_mnt"
|
|
_any=1
|
|
else
|
|
echo " WARNING: Could not unmount $_mnt — a reboot will restore original files."
|
|
fi
|
|
fi
|
|
done
|
|
[ "$_any" -eq 0 ] && echo " No overlays active."
|
|
|
|
# Nested-snapshot staging trees are bind mounts that PIN their ZFS snapshots, so
|
|
# leaving them mounted blocks those snapshots from ever being destroyed. The
|
|
# overlays above are volatile, but these are not self-healing without a reboot,
|
|
# and recover.sh is expected to work without one.
|
|
echo "Unmounting nested-snapshot staging trees ..."
|
|
# Best-effort: never block recovery. Same tested implementation as uninstall.sh.
|
|
python3 "$PATCH_DIR/patch/truecloud_nested.py" cleanup || true
|
|
|
|
# Cancel a deferred boot restart if one is still queued — we restart ourselves.
|
|
systemctl stop truecloud-mw-restart.service 2>/dev/null
|
|
systemctl reset-failed truecloud-mw-restart.service 2>/dev/null
|
|
|
|
echo "Restarting middlewared ..."
|
|
if systemctl restart middlewared; then
|
|
echo ""
|
|
echo "middlewared started successfully."
|
|
echo "Your system is back to normal (Storj-only TrueCloud Backup)."
|
|
else
|
|
echo ""
|
|
echo "WARNING: middlewared did not start cleanly even with the patch disabled."
|
|
echo "The problem is unrelated to truecloud-patch."
|
|
echo "Check the system log for details:"
|
|
echo " journalctl -u middlewared -n 50"
|
|
exit 1
|
|
fi
|
|
echo ""
|
|
echo "To re-enable the patch once you have investigated:"
|
|
echo " rm $PATCH_DIR/disabled"
|
|
echo " bash $PATCH_DIR/patch/apply.sh"
|
|
echo " systemctl restart middlewared"
|