mirror of
https://github.com/casjaysdevdocker/gitea
synced 2026-09-05 00:55:24 -04:00
🔧 Fix Gitea API token auth and container restart/runner races 🔧
Gitea config: `ALLOWED_HOST_LIST` was misplaced under `[webhook]` — the current config-cheat-sheet places it under `[security]` (default `external`), where it gates outbound webhook/OAuth2 calls. Left at its `[webhook]` default of unset (no such key there), `[security] ALLOWED_HOST_LIST` silently fell back to `external`, blocking internal-facing calls triggered by API actions like org creation and surfacing as an opaque 502 through the reverse proxy. Also pinned `DISABLE_QUERY_AUTH_TOKEN=false` explicitly, since Gitea flips its default to `true` in 1.23 (deprecated in 1.24) and this image always builds against the latest Gitea release — leaving it unset would silently downgrade `?token=` API calls to anonymous on the next image rebuild. Runtime/entrypoint: hardened `grep`/`type -t | grep` calls with `--` across the entrypoint function library and init.d scripts to stop values starting with `-` from being parsed as flags; guarded the entrypoint and `__no_exit` monitor-loop PID-reuse checks with a cmdline marker (PID namespaces reset on `docker restart` but `/run` persists, so a recorded PID can coincidentally be reused by an unrelated process and falsely appear "still running"); added a stale `/tmp/docker.pid` cleanup before each dockerd start attempt for the same reason; added `NO_COLOR`-aware plain-text fallbacks for emoji status banners; renamed the `su_cmd` helper to `__su_cmd` for naming consistency with other private functions; added `fuse-overlayfs` as the Docker-in-Docker storage driver. act_runner: removed the legacy single "gitea"-named runner registration and daemon start in `zz-act_runner.sh` — `start-runners` already owns all runner registration/count via `RUNNERS_START`, and running both duplicated runners. Registration now targets `127.0.0.1` instead of the detected external IPv4 address, which is transient/wrong under Docker-in-Docker networking and caused "no route to host" registration failures. Long-running background jobs (`cache-server`, `start-runners`) now redirect stdout/stderr to real log files and are `disown`ed instead of inheriting the `__post_execute` pipe — otherwise the `tee` reading that pipe never sees EOF and `__run_start_script` hangs forever waiting on a process that never exits. `start-runners` gained a version-stamp header and builds `RUNNER_LABELS` from an array instead of one long string for readability; its `ERR` trap and ports list now respect `NO_COLOR`. - rootfs/tmp/etc/gitea/app.ini: move `ALLOWED_HOST_LIST` to `[security]`; add explicit `DISABLE_QUERY_AUTH_TOKEN=false` - rootfs/tmp/etc/docker/daemon.json: add `storage-driver: fuse-overlayfs` - rootfs/usr/local/bin/entrypoint.sh: version bump; `grep --` hardening; cmdline-marker PID-reuse guard; `exit 0` instead of bare `exit` - rootfs/usr/local/bin/start-runners: add version-stamp header; `NO_COLOR`-aware ERR trap; build `RUNNER_LABELS` from an array - rootfs/usr/local/etc/docker/functions/entrypoint.sh: version bump; `grep --` hardening across helpers; `__no_exit` monitor-loop cmdline-marker guard; `NO_COLOR`-aware service banners; rename `su_cmd` to `__su_cmd` - rootfs/usr/local/etc/docker/init.d/05-dockerd.sh: version bump; `NO_COLOR`-aware messages; stale `/tmp/docker.pid` cleanup before start; `symlink`/`su_cmd` calls updated to `__symlink`/`__su_cmd`; `grep --` hardening; add `storage-driver` to both daemon.json heredocs - rootfs/usr/local/etc/docker/init.d/08-gitea.sh: version bump; `NO_COLOR`-aware messages (including stale-PID-file cleanup); `grep --` hardening; `su_cmd` call updated to `__su_cmd` - rootfs/usr/local/etc/docker/init.d/zz-act_runner.sh: version bump; remove legacy duplicate runner registration/daemon start; register against `127.0.0.1`; redirect and disown long-running background jobs to prevent pipe hangs; `NO_COLOR`-aware messages
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
#!/usr/bin/env bash
|
||||
# shellcheck shell=bash
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
##@Version : 202606261500-git
|
||||
##@Version : 202609030524-git
|
||||
# @@Author : Jason Hempstead
|
||||
# @@Contact : jason@casjaysdev.pro
|
||||
# @@License : WTFPL
|
||||
@@ -20,6 +20,8 @@
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
# shellcheck disable=SC1001,SC1003,SC2001,SC2003,SC2016,SC2031,SC2090,SC2115,SC2120,SC2155,SC2199,SC2229,SC2317,SC2329
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
VERSION="202609030524-git"
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
# run trap command on exit
|
||||
trap 'retVal=$?;[ "$SERVICE_IS_RUNNING" != "yes" ] && [ -f "$SERVICE_PID_FILE" ] && rm -Rf "$SERVICE_PID_FILE";exit $retVal' INT TERM
|
||||
trap 'retVal=$?;[ "$SERVICE_IS_RUNNING" != "yes" ] && [ -f "$SERVICE_PID_FILE" ] && rm -Rf "$SERVICE_PID_FILE";exit $retVal' SIGPWR 2>/dev/null || true
|
||||
@@ -330,7 +332,7 @@ if [ "$ENTRYPOINT_FIRST_RUN" != "no" ]; then
|
||||
# if ipv6 add it to /etc/hosts
|
||||
if [ "$UPDATE_FILE_HOSTS" = "yes" ]; then
|
||||
echo "# known hostname mappings" >"/etc/hosts" 2>/dev/null || true
|
||||
if [ -n "$(ip a 2>/dev/null | grep 'inet6.*::' || ifconfig 2>/dev/null | grep 'inet6.*::')" ]; then
|
||||
if [ -n "$(ip a 2>/dev/null | grep -- 'inet6.*::' || ifconfig 2>/dev/null | grep -- 'inet6.*::')" ]; then
|
||||
__printf_space "40" "::1" "localhost" >>"/etc/hosts" 2>/dev/null || true
|
||||
__printf_space "40" "127.0.0.1" "localhost" >>"/etc/hosts" 2>/dev/null || true
|
||||
else
|
||||
@@ -371,7 +373,7 @@ if [ "$ENTRYPOINT_FIRST_RUN" != "no" ]; then
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
# import hosts file into container
|
||||
if [ -f "/usr/local/etc/hosts" ] && [ "$UPDATE_FILE_HOSTS" = "yes" ]; then
|
||||
grep -vF "$HOSTNAME" "/usr/local/etc/hosts" 2>/dev/null >>"/etc/hosts" || true
|
||||
grep -vF -- "$HOSTNAME" "/usr/local/etc/hosts" 2>/dev/null >>"/etc/hosts" || true
|
||||
fi
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
# import resolv.conf file into container
|
||||
@@ -431,9 +433,16 @@ fi
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
# if no pid assume container restart - clean stale files on restart
|
||||
if [ -f "$ENTRYPOINT_PID_FILE" ]; then
|
||||
# Check if the PID in the file is still running
|
||||
# Check if the PID in the file is still running. /run persists across
|
||||
# `docker restart` (same container filesystem), but the PID namespace
|
||||
# resets every restart, so a recorded PID can coincidentally be reused by
|
||||
# an unrelated early-boot process in the new namespace. A bare `kill -0`
|
||||
# would then wrongly treat this as "entrypoint already running" and skip
|
||||
# __start_init_scripts entirely on a genuine restart, so also require the
|
||||
# live process's own cmdline to actually be this entrypoint script.
|
||||
entrypoint_pid=$(<"$ENTRYPOINT_PID_FILE") 2>/dev/null
|
||||
if [ -n "$entrypoint_pid" ] && kill -0 "$entrypoint_pid" 2>/dev/null; then
|
||||
if [ -n "$entrypoint_pid" ] && kill -0 "$entrypoint_pid" 2>/dev/null \
|
||||
&& grep -q -- "entrypoint.sh" "/proc/$entrypoint_pid/cmdline" 2>/dev/null; then
|
||||
# Process is still running, don't restart services
|
||||
START_SERVICES="no"
|
||||
touch "$ENTRYPOINT_PID_FILE"
|
||||
@@ -550,7 +559,7 @@ cron)
|
||||
shift 1
|
||||
__cron "$@" &
|
||||
__log_info "Cron script is running with PID: $!"
|
||||
exit
|
||||
exit 0
|
||||
;;
|
||||
# backup data and config dirs
|
||||
backup)
|
||||
@@ -581,7 +590,7 @@ healthcheck)
|
||||
services+="$name "
|
||||
done
|
||||
fi
|
||||
services="$(printf '%s\n' $services | sort -u | grep -v '^$')"
|
||||
services="$(printf '%s\n' $services | sort -u | grep -v -- '^$')"
|
||||
for proc in $services; do
|
||||
if [ -n "$proc" ]; then
|
||||
if ! __pgrep "$proc"; then
|
||||
@@ -592,7 +601,7 @@ healthcheck)
|
||||
done
|
||||
for port in $healthPorts; do
|
||||
if command -v netstat &>/dev/null && [ -n "$port" ]; then
|
||||
if ! netstat -taupln | grep -q ":$port "; then
|
||||
if ! netstat -taupln | grep -q -- ":$port "; then
|
||||
echo "$port isn't open" >&2
|
||||
healthStatus=$((healthStatus + 1))
|
||||
fi
|
||||
@@ -622,7 +631,7 @@ ports)
|
||||
# show running processes
|
||||
procs)
|
||||
shift 1
|
||||
ps="$(__ps axco command 2>/dev/null | grep -vE '^(COMMAND|grep|ps)$' | sort -u)"
|
||||
ps="$(__ps axco command 2>/dev/null | grep -vE -- '^(COMMAND|grep|ps)$' | sort -u)"
|
||||
[ -n "$ps" ] && printf '%s\n%s\n' "Found the following processes" "$ps" | tr '\n' ' '
|
||||
exit $?
|
||||
;;
|
||||
@@ -659,7 +668,7 @@ start)
|
||||
if [ $# -eq 0 ]; then
|
||||
scripts="$(ls -A "/usr/local/etc/docker/init.d")"
|
||||
[ -n "$scripts" ] && echo "$scripts" || echo "No scripts found in: /usr/local/etc/docker/init.d"
|
||||
exit
|
||||
exit 0
|
||||
elif [ "$1" = "all" ]; then
|
||||
shift $#
|
||||
if [ "$START_SERVICES" = "yes" ]; then
|
||||
|
||||
@@ -1,8 +1,31 @@
|
||||
#!/usr/bin/env bash
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
# shellcheck shell=bash
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
##@Version : 202609030524-git
|
||||
# @@Author : Jason Hempstead
|
||||
# @@Contact : jason@casjaysdev.pro
|
||||
# @@License : LICENSE.md
|
||||
# @@ReadME : start-runners --help
|
||||
# @@Copyright : Copyright: (c) 2026 Jason Hempstead, Casjays Developments
|
||||
# @@Created : Friday, Jun 05, 2026 18:14 EDT
|
||||
# @@File : start-runners
|
||||
# @@Description : Start act runners
|
||||
# @@Changelog : New script
|
||||
# @@TODO : Better documentation
|
||||
# @@Other :
|
||||
# @@Resource :
|
||||
# @@Terminal App : no
|
||||
# @@sudo/root : no
|
||||
# @@Template : shell/bash
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
# shellcheck disable=SC1001,SC1003,SC2001,SC2003,SC2016,SC2031,SC2090,SC2115,SC2120,SC2155,SC2199,SC2229,SC2317,SC2329
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
VERSION="202609030524-git"
|
||||
set -e
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
trap 'retVal=$?; echo "❌ Fatal error occurred: Exit code $retVal at line $LINENO in command: $BASH_COMMAND"; kill -TERM 1' ERR
|
||||
trap 'retVal=$?; emoji=$( [ -z "$NO_COLOR" ] && echo "❌ " || echo "" ); \
|
||||
echo "${emoji}Fatal error occurred: Exit code $retVal at line $LINENO in command: $BASH_COMMAND"; \
|
||||
kill -TERM 1' ERR
|
||||
trap 'retVal=$?;if [ "$SERVICE_IS_RUNNING" != "yes" ] && [ -f "$SERVICE_PID_FILE" ]; then rm -Rf "$SERVICE_PID_FILE"; fi;exit $retVal' SIGINT SIGTERM SIGPWR
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
# Function to __log messages with timestamp
|
||||
@@ -33,7 +56,37 @@ if [ -z "$SERVER_TOKEN" ]; then
|
||||
exit 1
|
||||
fi
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
RUNNER_LABELS="${RUNNER_LABELS:-linux:host,node14:docker://node:14,node16:docker://node:16,node18:docker://node:18,node20:docker://node:20,node22:docker://node:22,node:docker://node:latest,perl:docker://perl:latest,ruby:docker://ruby:latest,python:docker://python:latest,python3:docker://python:latest,php7:docker://casjaysdevdocker/php:7,php8:docker://casjaysdevdocker/php:8,php:docker://casjaysdevdocker/php:latest,alpine:docker://casjaysdev/alpine:latest,debian:docker://casjaysdev/debian:latest,ubuntu:docker://casjaysdev/ubuntu:latest,rhel:docker://casjaysdev/almalinux:latest,redhat:docker://casjaysdev/almalinux:latest,almalinux:docker://casjaysdev/almalinux:latest,act_runner:docker://catthehacker/ubuntu:full-latest,ubuntu-latest:docker://catthehacker/ubuntu:full-latest}"
|
||||
if [ -z "$RUNNER_LABELS" ]; then
|
||||
_default_runner_labels=(
|
||||
"linux:host"
|
||||
"node14:docker://node:14"
|
||||
"node16:docker://node:16"
|
||||
"node18:docker://node:18"
|
||||
"node20:docker://node:20"
|
||||
"node22:docker://node:22"
|
||||
"node:docker://node:latest"
|
||||
"perl:docker://perl:latest"
|
||||
"ruby:docker://ruby:latest"
|
||||
"python:docker://python:latest"
|
||||
"python3:docker://python:latest"
|
||||
"php7:docker://casjaysdevdocker/php:7"
|
||||
"php8:docker://casjaysdevdocker/php:8"
|
||||
"php:docker://casjaysdevdocker/php:latest"
|
||||
"alpine:docker://casjaysdev/alpine:latest"
|
||||
"debian:docker://casjaysdev/debian:latest"
|
||||
"ubuntu:docker://casjaysdev/ubuntu:latest"
|
||||
"rhel:docker://casjaysdev/almalinux:latest"
|
||||
"redhat:docker://casjaysdev/almalinux:latest"
|
||||
"almalinux:docker://casjaysdev/almalinux:latest"
|
||||
"act_runner:docker://catthehacker/ubuntu:full-latest"
|
||||
"ubuntu-latest:docker://catthehacker/ubuntu:full-latest"
|
||||
)
|
||||
RUNNER_LABELS="$(
|
||||
IFS=,
|
||||
echo "${_default_runner_labels[*]}"
|
||||
)"
|
||||
unset _default_runner_labels
|
||||
fi
|
||||
# Determine number of runners to start
|
||||
RUNNERS_START=${RUNNERS_START:-1}
|
||||
# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
|
||||
|
||||
Reference in New Issue
Block a user