🐛 Fix __random_password SIGPIPE abort under pipefail 🐛

App-breaking bug found during full runtime verification of the act_runner
cache-server feature: `__random_password()`'s `tr | head -c` pipeline
could be killed by SIGPIPE once `head -c` closes its input early, and
under `set -eo pipefail` this aborted the whole script.

- rootfs/usr/local/etc/docker/functions/entrypoint.sh: wrapped the
  `tr -dc ... | head -c...` pipeline in `{ ... } || true` so a SIGPIPE
  from `head` closing early no longer aborts the script
- TODO.AI.md: logged the fix and the upstream-template-sync follow-up
This commit is contained in:
2026-08-05 01:50:16 -04:00
parent 97270cfe91
commit 8990a72bd7
2 changed files with 9 additions and 1 deletions
+8
View File
@@ -21,6 +21,14 @@ Update Runbook in AI.md — `functions/entrypoint.sh` is normally regenerated, n
(the default). This was the root cause of the container dying immediately after printing only (the default). This was the root cause of the container dying immediately after printing only
the startup banner. Fixed by appending `|| true` to all 26 occurrences. the startup banner. Fixed by appending `|| true` to all 26 occurrences.
## App-breaking bug fixed — __random_password() SIGPIPE (functions/entrypoint.sh)
Needs syncing back to the upstream template in `casjay-dotfiles/scripts` per the Docker Template
Update Runbook in AI.md — `functions/entrypoint.sh` is normally regenerated, not hand-edited.
- `__random_password()` (~line 333): `tr | head -c` pipeline died under `set -eo pipefail` on
SIGPIPE. Fixed by wrapping in `{ ... } || true`.
## Other observations not yet actioned ## Other observations not yet actioned
- `.gitea/workflows/docker.yaml` uses the same stale/unpinned action pattern (`@v2`-`@v4`, DockerHub-only, `catthehacker/ubuntu:act-latest`) that was removed from the `opengist` repo's duplicate workflow — no `build.yml` counterpart exists here yet. - `.gitea/workflows/docker.yaml` uses the same stale/unpinned action pattern (`@v2`-`@v4`, DockerHub-only, `catthehacker/ubuntu:act-latest`) that was removed from the `opengist` repo's duplicate workflow — no `build.yml` counterpart exists here yet.
@@ -330,7 +330,7 @@ __find_mongodb_conf() {
find -L '/etc/mongodb' '/etc' -maxdepth 4 -type f \( -name 'mongod.conf' -o -name 'mongodb.conf' \) 2>/dev/null | head -n1 find -L '/etc/mongodb' '/etc' -maxdepth 4 -type f \( -name 'mongod.conf' -o -name 'mongodb.conf' \) 2>/dev/null | head -n1
} }
# - - - - - - - - - - - - - - - - - - - - - - - - - # - - - - - - - - - - - - - - - - - - - - - - - - -
__random_password() { tr -dc '0-9a-zA-Z' < /dev/urandom | head -c${1:-16} && echo ""; } __random_password() { { tr -dc '0-9a-zA-Z' < /dev/urandom | head -c"${1:-16}"; } || true; echo ""; }
# - - - - - - - - - - - - - - - - - - - - - - - - - # - - - - - - - - - - - - - - - - - - - - - - - - -
__init_working_dir() { __init_working_dir() {
# get service name # get service name