From b8f6c904684224375d843772238dfc943d710eb9 Mon Sep 17 00:00:00 2001 From: casjay Date: Sun, 24 May 2026 12:27:50 -0400 Subject: [PATCH] =?UTF-8?q?=F0=9F=97=83=EF=B8=8F=20Updated=20the=20functio?= =?UTF-8?q?ns=20file=20=F0=9F=97=83=EF=B8=8F?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit rootfs/usr/local/etc/docker/functions/entrypoint.sh --- .../local/etc/docker/functions/entrypoint.sh | 1070 +++++++++++------ 1 file changed, 719 insertions(+), 351 deletions(-) diff --git a/rootfs/usr/local/etc/docker/functions/entrypoint.sh b/rootfs/usr/local/etc/docker/functions/entrypoint.sh index 004e0f2..10642d8 100644 --- a/rootfs/usr/local/etc/docker/functions/entrypoint.sh +++ b/rootfs/usr/local/etc/docker/functions/entrypoint.sh @@ -1,7 +1,7 @@ #!/usr/bin/env bash # shellcheck shell=bash -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -##@Version : 202407241259-git +# - - - - - - - - - - - - - - - - - - - - - - - - - +##@Version : 202605241142-git # @@Author : Jason Hempstead # @@Contact : git-admin@casjaysdev.pro # @@License : LICENSE.md @@ -17,15 +17,36 @@ # @@Terminal App : no # @@sudo/root : no # @@Template : functions/docker-entrypoint -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -# shellcheck disable=SC1001,SC1003,SC2001,SC2003,SC2016,SC2031,SC2120,SC2155,SC2199,SC2317,SC2329 -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - +# shellcheck disable=SC1001,SC1003,SC2001,SC2003,SC2016,SC2031,SC2090,SC2115,SC2120,SC2155,SC2199,SC2229,SC2317,SC2329 +# - - - - - - - - - - - - - - - - - - - - - - - - - # setup debugging - https://www.gnu.org/software/bash/manual/html_node/The-Set-Builtin.html -[ -f "/config/.debug" ] && [ -z "$DEBUGGER_OPTIONS" ] && export DEBUGGER_OPTIONS="$(<"/config/.debug")" || DEBUGGER_OPTIONS="${DEBUGGER_OPTIONS:-}" -{ [ "$DEBUGGER" = "on" ] || [ -f "/config/.debug" ]; } && echo "Enabling debugging" && set -xo pipefail -x$DEBUGGER_OPTIONS && export DEBUGGER="on" || set -o pipefail -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -__remove_extra_spaces() { sed 's/\( \)*/\1/g;s|^ ||g'; } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +if [ -f "/config/.debug" ] && [ -z "$DEBUGGER_OPTIONS" ]; then + export DEBUGGER_OPTIONS="$(<"/config/.debug")" +fi +if [ "$DEBUGGER" = "on" ] || [ -f "/config/.debug" ]; then + set -o pipefail + [ -n "$DEBUGGER_OPTIONS" ] && set -"$DEBUGGER_OPTIONS" + export DEBUGGER="on" +else + set -o pipefail +fi +# - - - - - - - - - - - - - - - - - - - - - - - - - +__remove_extra_spaces() { sed -E 's/ +/ /g; s|^ ||'; } +# - - - - - - - - - - - - - - - - - - - - - - - - - +__log_debug() { + [ "$DEBUGGER" = "on" ] && echo "[DEBUG] $*" >&2 +} +__log_info() { + echo "[INFO] $*" +} +__log_warn() { + echo "[WARN] $*" >&2 +} +__log_error() { + echo "[ERROR] $*" >&2 +} +# - - - - - - - - - - - - - - - - - - - - - - - - - __printf_space() { local pad=$(printf '%0.1s' " "{1..60}) local padlength=$1 @@ -37,75 +58,142 @@ __printf_space() { message+="$(printf '%s\n' "$string2") " printf '%s\n' "$message" } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -__rm() { [ -n "$1" ] && [ -e "$1" ] && rm -Rf "${1:?}"; } -__grep_test() { grep -sh "$1" "$2" | grep -qwF "${3:-$1}" || return 1; } -__netstat() { [ -f "$(type -P netstat)" ] && netstat "$@" || return 10; } -__cd() { { [ -d "$1" ] || mkdir -p "$1"; } && builtin cd "$1" || return 1; } -__is_in_file() { [ -e "$2" ] && grep -Rsq "$1" "$2" && return 0 || return 1; } -__curl() { curl -q -sfI --max-time 3 -k -o /dev/null "$@" &>/dev/null || return 10; } -__find() { find "$1" -mindepth 1 -type ${2:-f,d} 2>/dev/null | grep '.' || return 10; } -__pcheck() { [ -n "$(which pgrep 2>/dev/null)" ] && pgrep -x "$1" &>/dev/null || return 10; } -__file_exists_with_content() { [ -n "$1" ] && [ -f "$1" ] && [ -s "$1" ] && return 0 || return 2; } -__sed() { sed -i 's|'$1'|'$2'|g' "$3" &>/dev/null || sed -i "s|$1|$2|g" "$3" &>/dev/null || return 1; } -__ps() { [ -f "$(type -P ps)" ] && ps "$@" 2>/dev/null | sed 's|:||g' | grep -Fw " ${1:-$SERVICE_NAME}$" || return 10; } -__is_dir_empty() { if [ -n "$1" ]; then [ "$(ls -A "$1" 2>/dev/null | wc -l)" -eq 0 ] && return 0 || return 1; else return 1; fi; } -__get_ip6() { ip a 2>/dev/null | grep -w 'inet6' | awk '{print $2}' | grep -vE '^::1|^fe' | sed 's|/.*||g' | head -n1 | grep '.' || echo ''; } -__get_ip4() { ip a 2>/dev/null | grep -w 'inet' | awk '{print $2}' | grep -vE '^127.0.0' | sed 's|/.*||g' | head -n1 | grep '.' || echo '127.0.0.1'; } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - +__mkdir() { + if [ -n "$1" ]; then + if ! mkdir -p "$@" 2>/dev/null; then + [ "$DEBUGGER" = "on" ] && echo "Warning: Failed to create directory: $*" >&2 + return 1 + fi + fi + return 0 +} +__rm() { + if [ -n "$1" ] && [ -e "$1" ]; then + if ! rm -Rf "${1:?}" 2>/dev/null; then + [ "$DEBUGGER" = "on" ] && echo "Warning: Failed to remove: $1" >&2 + return 1 + fi + fi + return 0 +} +__grep_test() { grep -sh "$1" "$2" 2>/dev/null | grep -qwF "${3:-$1}"; } +__netstat() { + command -v netstat &>/dev/null || { + [ "$DEBUGGER" = "on" ] && echo "Warning: netstat command not found" >&2 + return 10 + } + netstat "$@" 2>/dev/null +} +__cd() { + [ -d "$1" ] || mkdir -p "$1" 2>/dev/null || return 1 + builtin cd "$1" || return 1 +} +__is_in_file() { [ -e "$2" ] && grep -Rsq "$1" "$2" 2>/dev/null; } +__curl() { curl -q -sfI --max-time 3 -k -o /dev/null "$@" 2>/dev/null || return 10; } +__find() { + local result + result=$(find "$1" -mindepth 1 -type "${2:-f,d}" 2>/dev/null) + [ -n "$result" ] || return 10 + printf '%s\n' "$result" +} +__pcheck() { + command -v pgrep &>/dev/null && pgrep -x "$1" &>/dev/null || return 10 +} +__file_exists_with_content() { [ -n "$1" ] && [ -f "$1" ] && [ -s "$1" ] || return 2; } +__sed() { sed -i "s|$1|$2|g" "$3" 2>/dev/null || return 1; } +__ps() { + command -v ps &>/dev/null || return 10 + ps "$@" 2>/dev/null | sed 's|:||g' | grep -Fw " ${1:-$SERVICE_NAME}$" || return 10 +} +__is_dir_empty() { + [ -n "$1" ] && [ -d "$1" ] || return 1 + [ -z "$(ls -A "$1" 2>/dev/null)" ] +} +__get_ip6() { + ip a 2>/dev/null | awk '/^[[:space:]]*inet6 / { + split($2, a, "/"); ip = a[1] + if (ip !~ /^::1$/ && ip !~ /^fe/) { print ip; exit } + }' +} +__get_ip4() { + local ip4 + ip4=$(ip a 2>/dev/null | awk '/^[[:space:]]*inet / { + split($2, a, "/"); ip = a[1] + if (ip !~ /^127\.0\.0/) { print ip; exit } + }') + echo "${ip4:-127.0.0.1}" +} +__find_and_remove() { + find "${2:-/etc}" -iname "$1" -exec rm -Rfv {} \; 2>/dev/null || true +} +# - - - - - - - - - - - - - - - - - - - - - - - - - __pgrep() { - local count=3 - local srvc="${1:-SERVICE_NAME}" + local srvc="$1" count=3 + [ -z "$srvc" ] && return 10 while [ $count -ge 0 ]; do - # Use exact process name matching, not full command line search - pgrep -x "$srvc" >/dev/null 2>&1 && return 0 - sleep 1 + pgrep -x "$srvc" &>/dev/null && return 0 + pgrep -f "$srvc" &>/dev/null && return 0 + ps -eo comm 2>/dev/null | grep -qxF "$srvc" && return 0 + [ $count -gt 0 ] && sleep 1 count=$((count - 1)) done return 10 } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __find_file_relative() { [ -e "$1" ] || return 0 - find "$1"/* -not -path '*env/*' -not -path '.git*' -type f 2>/dev/null | sed 's|'$1'/||g' | sort -u | grep -v '^$' | grep '.' || false + find "$1"/* -not -path '*env/*' -not -path '*/.git/*' -not -name '.git' -type f 2>/dev/null \ + | sort -u \ + | sed "s|^$1/||" || true } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __find_directory_relative() { [ -d "$1" ] || return 0 - find "$1"/* -not -path '*env/*' -not -path '.git*' -type d 2>/dev/null | sed 's|'$1'/||g' | sort -u | grep -v '^$' | grep '.' || false + find "$1"/* -not -path '*env/*' -not -path '*/.git/*' -not -name '.git' -type d 2>/dev/null \ + | sort -u \ + | sed "s|^$1/||" || true } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -__pid_exists() { - local result="" - result="$(ps -ax --no-header 2>/dev/null | sed 's/^[[:space:]]*//g' | awk -F' ' '{print $1}' | sed 's|:||g' | grep '[0-9]' | sort -uV | grep "^$1$" 2>/dev/null || echo '')" - [ -n "$result" ] && return 0 || return 1 -} -__is_running() { - local result="" - result="$(ps -eo args --no-header 2>/dev/null | awk '{print $1,$2,$3}' | sed 's|:||g' | sort -u | grep -vE 'grep|COMMAND|awk|tee|ps|sed|sort|tail' | grep "$1" | grep "${2:-^}" 2>/dev/null || echo '')" - [ -n "$result" ] && return 0 || return 1 -} -__get_pid() { - local result="" - result="$(ps -ax --no-header 2>/dev/null | sed 's/^[[:space:]]*//g;s|;||g;s|:||g' | awk '{print $1,$5}' | sed 's|:||g' | grep "$1$" | grep -v 'grep' | awk -F' ' '{print $1}' | grep '[0-9]' | sort -uV | head -n1 | grep '.' 2>/dev/null || echo '')" - if [ -n "$result" ]; then - echo "$result" - return 0 +# - - - - - - - - - - - - - - - - - - - - - - - - - +__pid_exists() { [ -n "$1" ] && [ -d "/proc/$1" ]; } +__is_running() { + local pat="$1" + [ -n "$2" ] && pat="$pat.*$2" + if command -v pgrep &>/dev/null; then + pgrep -f "$pat" &>/dev/null else - return 1 + ps -eo args 2>/dev/null | grep -v grep | grep -Eq "$pat" fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -__format_variables() { printf '%s\n' "${@//,/ }" | tr ' ' '\n' | sort -RVu | grep -v '^$' | tr '\n' ' ' | __clean_variables | grep '.' || return 0; } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +__get_pid() { + if [ -z "$1" ]; then + [ "$DEBUGGER" = "on" ] && echo "Warning: __get_pid called without process name" >&2 + return 1 + fi + local pid + pid=$(pgrep -x -n "$1" 2>/dev/null) + if [ -n "$pid" ]; then + echo "$pid" + return 0 + fi + [ "$DEBUGGER" = "on" ] && echo "Debug: No PID found for process: $1" >&2 + return 1 +} +# - - - - - - - - - - - - - - - - - - - - - - - - - +__format_variables() { + local input="${*//,/ }" + [ -z "$input" ] && return 0 + printf '%s\n' $input | sort -Ru | tr '\n' ' ' +} +# - - - - - - - - - - - - - - - - - - - - - - - - - __clean_variables() { local var="$*" - var="${var#"${var%%[![:space:]]*}"}" # remove leading whitespace characters - var="${var%"${var##*[![:space:]]}"}" # remove trailing whitespace characters - var="$(printf '%s\n' "$var" | sed 's/\( \)*/\1/g;s|^ ||g')" - printf '%s' "$var" | grep -v '^$' + var="${var#"${var%%[![:space:]]*}"}" + var="${var%"${var##*[![:space:]]}"}" + while [[ $var == *" "* ]]; do var="${var// / }"; done + [ -n "$var" ] && printf '%s' "$var" } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __no_exit() { local monitor_interval="${SERVICE_MONITOR_INTERVAL:-60}" local failure_threshold="${SERVICE_FAILURE_THRESHOLD:-3}" @@ -113,54 +201,66 @@ __no_exit() { local failed_services="" local failure_count=0 - [ -f "/run/.no_exit.pid" ] && return 0 + # only return early if the recorded PID is still alive; a leftover + # pid file from a prior container life (docker restart) would otherwise + # cause us to exit instead of entering the monitor loop. + if [ -f "/run/.no_exit.pid" ]; then + local no_exit_pid + no_exit_pid=$(<"/run/.no_exit.pid") 2>/dev/null + if [ -n "$no_exit_pid" ] && kill -0 "$no_exit_pid" 2>/dev/null; then + return 0 + fi + rm -f /run/.no_exit.pid 2>/dev/null || true + fi exec bash -c " trap 'echo \"Container shutdown requested\"; rm -f /run/.no_exit.pid /run/*.pid; exit 0' TERM INT echo \$\$ > /run/.no_exit.pid + failed_services=\"\" + failure_count=0 while true; do if [ -n \"$monitor_services\" ] && [ \"$monitor_services\" != \"tini\" ]; then for service in \$(echo \"$monitor_services\" | tr ',' ' '); do if [ \"\$service\" != \"tini\" ] && ! pgrep -x \"\$service\" >/dev/null 2>&1; then - echo \"⚠️ Service \$service is not running\" >&2 + echo \"WARNING: Service \$service is not running\" >&2 failed_services=\"\$failed_services \$service\" failure_count=\$((failure_count + 1)) fi done if [ \$failure_count -ge $failure_threshold ]; then - echo \"❌ Too many service failures (\$failure_count), exiting container\" >&2 + echo \"ERROR: Too many service failures (\$failure_count), exiting container\" >&2 exit 1 fi if [ -n \"\$failed_services\" ]; then - echo \"⚠️ Failed services:\$failed_services\" >&2 + echo \"WARNING: Failed services:\$failed_services\" >&2 failed_services=\"\" + failure_count=0 fi fi - sleep $monitor_interval - done & - wait + sleep $monitor_interval & wait \$! + done " } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __trim() { local var="${*//;/ }" - var="${var#"${var%%[![:space:]]*}"}" # remove leading whitespace characters - var="${var%"${var##*[![:space:]]}"}" # remove trailing whitespace characters - var="$(echo "$var" | __remove_extra_spaces | sed "s| |; |g;s|;$| |g" | __remove_extra_spaces)" - printf '%s' "$var" | sed 's|;||g' | grep -v '^$' + var="${var#"${var%%[![:space:]]*}"}" + var="${var%"${var##*[![:space:]]}"}" + while [[ $var == *" "* ]]; do var="${var// / }"; done + [ -n "$var" ] && printf '%s' "$var" } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __banner() { local message="$*" local total_width=80 local content_width=$((total_width - 14)) # Account for "# - - - " and " - - - #" printf '# - - - %-*s - - - #\n' "$content_width" "$message" } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __service_banner() { local icon="${1:-🔧}" local message="${2:-Processing}" @@ -172,23 +272,27 @@ __service_banner() { local text_width=$((content_width - icon_width * 2 - 2)) # Account for both icons and spaces printf '# - - - %s %-*s %s - - - #\n' "$icon" "$text_width" "$full_message" "$icon" } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -__find_php_bin() { find -L '/usr'/*bin -maxdepth 4 -name 'php-fpm*' 2>/dev/null | head -n1 | grep '.' || echo ''; } -__find_php_ini() { find -L '/etc' -maxdepth 4 -name 'php.ini' 2>/dev/null | head -n1 | sed 's|/php.ini||g' | grep '.' || echo ''; } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -__find_nginx_conf() { find -L '/etc' -maxdepth 4 -name 'nginx.conf' 2>/dev/null | head -n1 | grep '.' || echo ''; } -__find_caddy_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'caddy.conf' 2>/dev/null | head -n1 | grep '.' || echo ''; } -__find_lighttpd_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'lighttpd.conf' 2>/dev/null | head -n1 | grep '.' || echo ''; } -__find_cherokee_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'cherokee.conf' 2>/dev/null | head -n1 | grep '.' || echo ''; } -__find_httpd_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'httpd.conf' -o -iname 'apache2.conf' 2>/dev/null | head -n1 | grep '.' || echo ''; } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -__find_mysql_conf() { find -L '/etc' -maxdepth 4 -type f -name 'my.cnf' 2>/dev/null | head -n1 | grep '.' || echo ''; } -__find_pgsql_conf() { find -L '/var/lib' '/etc' -maxdepth 8 -type f -name 'postgresql.conf' 2>/dev/null | head -n1 | grep '.' || echo ''; } +# - - - - - - - - - - - - - - - - - - - - - - - - - +__find_php_bin() { find -L '/usr'/*bin -maxdepth 4 -name 'php-fpm*' 2>/dev/null | head -n1; } +__find_php_ini() { + local f + f=$(find -L '/etc' -maxdepth 4 -name 'php.ini' 2>/dev/null | head -n1) + [ -n "$f" ] && printf '%s\n' "${f%/php.ini}" +} +# - - - - - - - - - - - - - - - - - - - - - - - - - +__find_nginx_conf() { find -L '/etc' -maxdepth 4 -name 'nginx.conf' 2>/dev/null | head -n1; } +__find_caddy_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'caddy.conf' 2>/dev/null | head -n1; } +__find_lighttpd_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'lighttpd.conf' 2>/dev/null | head -n1; } +__find_cherokee_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'cherokee.conf' 2>/dev/null | head -n1; } +__find_httpd_conf() { find -L '/etc' -maxdepth 4 -type f -iname 'httpd.conf' -o -iname 'apache2.conf' 2>/dev/null | head -n1; } +# - - - - - - - - - - - - - - - - - - - - - - - - - +__find_mysql_conf() { find -L '/etc' -maxdepth 4 -type f -name 'my.cnf' 2>/dev/null | head -n1; } +__find_pgsql_conf() { find -L '/var/lib' '/etc' -maxdepth 8 -type f -name 'postgresql.conf' 2>/dev/null | head -n1; } __find_couchdb_conf() { return; } __find_mongodb_conf() { return; } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -__random_password() { cat "/dev/urandom" | tr -dc '0-9a-zA-Z' | head -c${1:-16} && echo ""; } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - +__random_password() { tr -dc '0-9a-zA-Z' < /dev/urandom | head -c${1:-16} && echo ""; } +# - - - - - - - - - - - - - - - - - - - - - - - - - __init_working_dir() { local service_name="$SERVICE_NAME" # get service name local workdir="$(eval echo "${WORK_DIR:-}")" # expand variables @@ -202,29 +306,46 @@ __init_working_dir() { [ -z "$WORK_DIR" ] && [ "$HOME" = "/root" ] && [ "$RUNAS_USER" != "root" ] && [ "$PWD" != "/tmp" ] && home="${workdir:-$home}" [ -z "$WORK_DIR" ] && [ "$HOME" = "/root" ] && [ "$SERVICE_USER" != "root" ] && [ "$PWD" != "/tmp" ] && home="${workdir:-$home}" # create needed directories - [ -n "$home" ] && { [ -d "$home" ] || mkdir -p "$home"; } - [ -n "$workdir" ] && { [ -d "$workdir" ] || mkdir -p "$workdir"; } - [ "$SERVICE_USER" = "root" ] || [ -d "$home" ] && chmod -f 777 "$home" - [ "$SERVICE_USER" = "root" ] || [ -d "$workdir" ] && chmod -f 777 "$workdir" - # - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + if [ -n "$home" ]; then + if [ ! -d "$home" ]; then + mkdir -p "$home" + fi + fi + if [ -n "$workdir" ]; then + if [ ! -d "$workdir" ]; then + mkdir -p "$workdir" + fi + fi + if [ "$SERVICE_USER" != "root" ] && [ -d "$home" ]; then + chmod -f 777 "$home" + fi + if [ "$SERVICE_USER" != "root" ] && [ -d "$workdir" ]; then + chmod -f 777 "$workdir" + fi + # - - - - - - - - - - - - - - - - - - - - - - - - - # cd to dir __cd "${workdir:-$home}" - # - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + # - - - - - - - - - - - - - - - - - - - - - - - - - echo "Setting the working directory to: $PWD" - # - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + # - - - - - - - - - - - - - - - - - - - - - - - - - export WORK_DIR="$workdir" HOME="$home" } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __exec_service() { local count=6 echo "Starting $1" eval "$@" 2>>/dev/stderr >>/data/logs/start.log & while [ $count -ne 0 ]; do sleep 3 - __pgrep $1 && touch "/run/init.d/$1.pid" && break || count=$((count - 1)) + if __pgrep "$1"; then + touch "/run/init.d/$1.pid" + break + else + count=$((count - 1)) + fi done } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __update_ssl_certs() { [ -f "/config/env/ssl.sh" ] && . "/config/env/ssl.sh" if [ -f "$SSL_CERT" ] && [ -f "$SSL_KEY" ]; then @@ -234,7 +355,7 @@ __update_ssl_certs() { [ -f "$SSL_CERT" ] && cp -Rf "$SSL_CERT" "/etc/ssl/$SSL_CERT" fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __certbot() { [ -n "$(type -P 'certbot')" ] || return 1 local options="$1" @@ -244,49 +365,74 @@ __certbot() { local ADD_CERTBOT_DOMAINS="" local CERTBOT_DOMAINS="${CERTBOT_DOMAINS:-$HOSTNAME}" local CERT_BOT_MAIL="${CERT_BOT_MAIL:-ssl-admin@$CERTBOT_DOMAINS}" - local certbot_key_opts="--key-path $SSL_KEY --fullchain-path $SSL_CERT" + local certbot_key_opts="" mkdir -p "/config/letsencrypt" __symlink "/etc/letsencrypt" "/config/letsencrypt" is_renewal="$(find /etc/letsencrypt/renewal -type f 2>/dev/null || false)" [ -f "/config/env/ssl.sh" ] && . "/config/env/ssl.sh" [ -f "/config/certbot/env.sh" ] && . "/config/certbot/env.sh" - [ -n "$SSL_KEY" ] && { mkdir -p "$(dirname "$SSL_KEY")" || true; } || { echo "The variable $SSL_KEY is not set" >&2 && return 1; } - [ -n "$SSL_CERT" ] && { mkdir -p "$(dirname "$SSL_CERT")" || true; } || { echo "The variable $SSL_CERT is not set" >&2 && return 1; } + if [ -n "$SSL_KEY" ]; then + mkdir -p "$(dirname "$SSL_KEY")" 2>/dev/null || true + else + echo "The variable SSL_KEY is not set" >&2 + return 1 + fi + if [ -n "$SSL_CERT" ]; then + mkdir -p "$(dirname "$SSL_CERT")" 2>/dev/null || true + else + echo "The variable SSL_CERT is not set" >&2 + return 1 + fi domain_list="$CERTBOT_DOMAINS www.$CERTBOT_DOMAINS mail.$CERTBOT_DOMAINS" domain_list="$(echo "$domain_list" | tr ' ' '\n' | sort -u | tr '\n' ' ')" - [ "$CERT_BOT_ENABLED" = "true" ] || { export CERT_BOT_ENABLED="" && return 10; } - [ -n "$CERT_BOT_MAIL" ] || { echo "The variable CERT_BOT_MAIL is not set" >&2 && return 1; } - [ -n "$CERTBOT_DOMAINS" ] || { echo "The variable CERTBOT_DOMAINS is not set" >&2 && return 1; } + if [ "$CERT_BOT_ENABLED" != "true" ]; then + export CERT_BOT_ENABLED="" + return 10 + fi + if [ -z "$CERT_BOT_MAIL" ]; then + echo "The variable CERT_BOT_MAIL is not set" >&2 + return 1 + fi + if [ -z "$CERTBOT_DOMAINS" ]; then + echo "The variable CERTBOT_DOMAINS is not set" >&2 + return 1 + fi for domain in $CERTBOT_DOMAINS; do [ -n "$domain" ] && ADD_CERTBOT_DOMAINS+="-d $domain " done - [ -n "$is_renewal" ] && options="renew" ADD_CERTBOT_DOMAINS="" || options="certonly" - certbot_key_opts="$certbot_key_opts $ADD_CERTBOT_DOMAINS" + local expand_opt="" + if [ -n "$is_renewal" ]; then + options="renew" + ADD_CERTBOT_DOMAINS="" + else + options="certonly" + expand_opt="--expand" + fi + certbot_key_opts="$ADD_CERTBOT_DOMAINS" if [ -f "/config/certbot/setup.sh" ]; then - eval "/config/certbot/setup.sh" + \bash "/config/certbot/setup.sh" statusCode=$? elif [ -f "/etc/named/certbot.sh" ]; then - eval "/etc/named/certbot.sh" + \bash "/etc/named/certbot.sh" statusCode=$? elif [ -f "/config/certbot/dns.conf" ]; then - if certbot $options -n --dry-run --agree-tos --expand --dns-rfc2136 --dns-rfc2136-credentials /config/certbot/dns.conf $certbot_key_opts; then - certbot $options -n --agree-tos --expand --dns-rfc2136 --dns-rfc2136-credentials /config/certbot/dns.conf $certbot_key_opts + if certbot $options -n --dry-run --agree-tos $expand_opt --dns-rfc2136 --dns-rfc2136-credentials /config/certbot/dns.conf $certbot_key_opts; then + certbot $options -n --agree-tos $expand_opt --dns-rfc2136 --dns-rfc2136-credentials /config/certbot/dns.conf $certbot_key_opts fi statusCode=$? elif [ -f "/config/certbot/certbot.conf" ]; then - if certbot $options -n --dry-run --agree-tos --expand --dns-rfc2136 --dns-rfc2136-credentials /config/certbot/certbot.conf $certbot_key_opts; then - certbot $options -n --agree-tos --expand --dns-rfc2136 --dns-rfc2136-credentials /config/certbot/certbot.conf $certbot_key_opts + if certbot $options -n --dry-run --agree-tos $expand_opt --dns-rfc2136 --dns-rfc2136-credentials /config/certbot/certbot.conf $certbot_key_opts; then + certbot $options -n --agree-tos $expand_opt --dns-rfc2136 --dns-rfc2136-credentials /config/certbot/certbot.conf $certbot_key_opts fi statusCode=$? elif [ -f "/config/named/certbot-update.conf" ]; then - if certbot $options -n --dry-run --agree-tos --expand --dns-rfc2136 --dns-rfc2136-credentials /config/named/certbot-update.conf $certbot_key_opts; then - certbot $options -n --agree-tos --expand --dns-rfc2136 --dns-rfc2136-credentials /config/named/certbot-update.conf $certbot_key_opts + if certbot $options -n --dry-run --agree-tos $expand_opt --dns-rfc2136 --dns-rfc2136-credentials /config/named/certbot-update.conf $certbot_key_opts; then + certbot $options -n --agree-tos $expand_opt --dns-rfc2136 --dns-rfc2136-credentials /config/named/certbot-update.conf $certbot_key_opts fi statusCode=$? else - certbot_key_opts="$certbot_key_opts --webroot ${WWW_ROOT_DIR:-/usr/local/share/httpd/default}" if [ -n "$ADD_CERTBOT_DOMAINS" ]; then - certbot $options --agree-tos -m $CERT_BOT_MAIL certonly --webroot "${WWW_ROOT_DIR:-/usr/local/share/httpd/default}" $certbot_key_opts + certbot $options --agree-tos -m $CERT_BOT_MAIL --webroot "${WWW_ROOT_DIR:-/usr/local/share/httpd/default}" $certbot_key_opts statusCode=$? else statusCode=1 @@ -295,21 +441,33 @@ __certbot() { [ $statusCode -eq 0 ] && __update_ssl_certs return $statusCode } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __display_user_info() { if [ -n "$user_name" ] || [ -n "$user_pass" ] || [ -n "$root_user_name" ] || [ -n "$root_user_pass" ]; then __banner "User info" - [ -n "$user_name" ] && __printf_space "40" "username:" "$user_name" && echo "$user_name" - [ -n "$user_pass" ] && __printf_space "40" "password:" "saved to ${USER_FILE_PREFIX}/${SERVICE_NAME}_pass" && echo "$user_pass" - [ -n "$root_user_name" ] && __printf_space "40" "root username:" "$root_user_name" && echo "$root_user_name" - [ -n "$root_user_pass" ] && __printf_space "40" "root password:" "saved to ${ROOT_FILE_PREFIX}/${SERVICE_NAME}_pass" && echo "$root_user_pass" + [ -n "$user_name" ] && __printf_space "40" "username:" "$user_name" + if [ -n "$user_pass" ]; then + if [ "${SHOW_PASSWORDS:-no}" = "yes" ]; then + __printf_space "40" "password:" "$user_pass" + else + __printf_space "40" "password:" "saved to ${USER_FILE_PREFIX}/${SERVICE_NAME}_pass" + fi + fi + [ -n "$root_user_name" ] && __printf_space "40" "root username:" "$root_user_name" + if [ -n "$root_user_pass" ]; then + if [ "${SHOW_PASSWORDS:-no}" = "yes" ]; then + __printf_space "40" "root password:" "$root_user_pass" + else + __printf_space "40" "root password:" "saved to ${ROOT_FILE_PREFIX}/${SERVICE_NAME}_pass" + fi + fi __banner "" fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __init_config_etc() { local copy="no" - local name="$(find "/etc/$SERVICE_NAME" -maxdepth 0 2>/dev/null | head -n1)" + local name="$SERVICE_NAME" local etc_dir="${ETC_DIR:-/etc/$name}" local conf_dir="${CONF_DIR:-/config/$name}" __is_dir_empty "$conf_dir" && copy=yes @@ -321,13 +479,16 @@ __init_config_etc() { __copy_templates "$etc_dir" "$conf_dir" fi fi - # - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + # - - - - - - - - - - - - - - - - - - - - - - - - - } __create_ssl_cert() { local SSL_DIR="${SSL_DIR:-/etc/ssl}" if ! __certbot certonly; then [ -f "/config/env/ssl.sh" ] && . "/config/env/ssl.sh" - [ -n "$SSL_DIR" ] || { echo "SSL_DIR is unset" && return 1; } + if [ -z "$SSL_DIR" ]; then + echo "SSL_DIR is unset" + return 1 + fi [ -d "$SSL_DIR" ] || mkdir -p "$SSL_DIR" if [ -n "$FORCE_SSL" ] || [ ! -f "$SSL_CERT" ] || [ ! -f "$SSL_KEY" ]; then echo "Setting Country to $COUNTRY and Setting State/Province to $STATE and Setting City to $CITY" @@ -353,7 +514,7 @@ __create_ssl_cert() { return 2 fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __init_apache() { local etc_dir="" conf_dir="" conf_dir="" www_dir="" apache_bin="" etc_dir="/etc/${1:-apache2}" @@ -363,7 +524,7 @@ __init_apache() { # return 0 } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __init_nginx() { local etc_dir="/etc/${1:-nginx}" local conf_dir="/config/${1:-nginx}" @@ -371,14 +532,14 @@ __init_nginx() { local nginx_bin="$(type -P 'nginx')" return 0 } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __init_php() { local etc_dir="/etc/${1:-php}" local conf_dir="/config/${1:-php}" local php_bin="${PHP_BIN_DIR:-$(__find_php_bin)}" return 0 } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __init_mysql() { local db_dir="/data/db/mysql" local etc_dir="${home:-/etc/${1:-mysql}}" @@ -391,28 +552,28 @@ __init_mysql() { local mysqld_bin="$(type -P 'mysqld')" return 0 } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __init_mongodb() { local home="${MONGODB_CONFIG_FILE:-$(__find_mongodb_conf)}" local user_name="${INITDB_ROOT_USERNAME:-root}" local user_pass="${MONGO_INITDB_ROOT_PASSWORD:-$_ROOT_PASSWORD}" return } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __init_postgres() { local home="${PGSQL_CONFIG_FILE:-$(__find_pgsql_conf)}" local user_name="${POSTGRES_USER:-root}" local user_pass="${POSTGRES_PASSWORD:-$POSTGRES_ROOT_PASSWORD}" return } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __init_couchdb() { local home="${COUCHDB_CONFIG_FILE:-$(__find_couchdb_conf)}" local user_name="${COUCHDB_USER:-root}" local user_pass="${COUCHDB_PASSWORD:-$SET_RANDOM_PASS}" return } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # Show available init functions __init_help() { echo ' @@ -422,69 +583,83 @@ __create_ssl_cert ' return } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __run_once() { - if [ "$CONFIG_DIR_INITIALIZED" = "false" ] || [ "$DATA_DIR_INITIALIZED" = "false" ] || [ ! -f "/config/.docker_has_run" ]; then + if [ "$CONFIG_DIR_INITIALIZED" = "no" ] || [ "$DATA_DIR_INITIALIZED" = "no" ] || [ ! -f "/config/.docker_has_run" ]; then return 0 else return 1 fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # run program ever n minutes __cron() { - trap 'retVal=$?;[ -f "/run/cron/$bin.run" ] && rm -Rf "/run/cron/$bin.run";[ -f "/run/cron/$bin.pid" ] && rm -Rf "/run/cron/$bin.pid";exit ${retVal:-0}' SIGINT ERR EXIT - [ "$1" = "--pid" ] && pid="$2" && shift 2 || pid="$$" - test -n "$1" && test -z "${1//[0-9]/}" && interval=$(($1 * 60)) && shift 1 || interval="300" + local bin="" + if [ "$1" = "--pid" ]; then + pid="$2" + shift 2 + else + pid="$$" + fi + if test -n "$1" && test -z "${1//[0-9]/}"; then + interval=$(($1 * 60)) + shift 1 + else + interval="300" + fi [ $# -eq 0 ] && echo "Usage: cron [interval] [command]" && exit 1 local command="$*" - local bin="$(basename "${CRON_NAME:-$1}")" + bin="${CRON_NAME:-$1}"; bin="${bin##*/}" + trap 'retVal=$?;[ -f "/run/cron/$bin.run" ] && rm -Rf "/run/cron/$bin.run";[ -f "/run/cron/$bin.pid" ] && rm -Rf "/run/cron/$bin.pid";exit ${retVal:-0}' SIGINT ERR EXIT [ -d "/run/cron" ] || mkdir -p "/run/cron" echo "$pid" >"/run/cron/$bin.pid" echo "$command" >"/run/cron/$bin.run" echo "Log is saved to /data/logs/cron.log" + # eval is intentional: $command is operator-controlled input from this container's init while :; do eval "$command" sleep $interval [ -f "/run/cron/$bin.run" ] || break done 2>/dev/stderr >>"/data/logs/cron.log" } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __replace() { local search="$1" replace="$2" file="${3:-$2}" [ -e "$file" ] || return 1 __sed "$search" "$replace" "$file" || return 0 } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __find_replace() { local search="$1" replace="$2" file="${3:-$2}" [ -e "$file" ] || return 1 - find "$file" -type f -not -path '.git*' -exec sed -i "s|$search|$replace|g" {} \; 2>/dev/null + find "$file" -type f -not -path '*/.git/*' -not -name '.git' -exec sed -i "s|$search|$replace|g" {} + 2>/dev/null } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # /config > /etc __copy_templates() { - local from="$1" to="$2" - is_link="$(ls -la "$dest" 2>/dev/null | awk '{print $NF}')" + local from="$1" to="$2" is_link="" + [ -L "$to" ] && is_link="$(readlink "$to")" [ "$from" != "$is_link" ] || return 0 - if [ -e "$from" ] && __is_dir_empty "$to"; then + if [ -e "$from" ] && (! [ -d "$to" ] || __is_dir_empty "$to"); then __file_copy "$from" "$to" fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # /config/file > /etc/file __symlink() { local from="$1" to="$2" - if [ -e "$to" ]; then - [ -e "$from" ] && __rm "$from" - ln -sf "$to" "$from" && echo "Created symlink to $from > $to" - fi + [ -e "$to" ] || return 0 + [ "$from" = "$to" ] && return 0 + __rm "$from" + [ -d "${from%/*}" ] || mkdir -p "${from%/*}" 2>/dev/null + ln -sf "$to" "$from" && echo "Created symlink to $from > $to" } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __file_copy() { local from="$1" local dest="$2" - is_link="$(ls -la "$dest" 2>/dev/null | awk '{print $NF}')" + local is_link="" + [ -L "$dest" ] && is_link="$(readlink "$dest")" if [ "$from" != "$is_link" ]; then if [ -n "$from" ] && [ -e "$from" ] && [ -n "$dest" ]; then if [ -d "$from" ]; then @@ -510,9 +685,9 @@ __file_copy() { fi fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __generate_random_uids() { - local set_random_uid="$(seq 100 999 | sort -R | head -n 1)" + local set_random_uid=$((100 + RANDOM % 900)) while :; do if grep -shq "x:.*:$set_random_uid:" "/etc/group" && ! grep -shq "x:$set_random_uid:.*:" "/etc/passwd"; then set_random_uid=$((set_random_uid + 1)) @@ -522,7 +697,7 @@ __generate_random_uids() { fi done } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __setup_directories() { APPLICATION_DIRS="${APPLICATION_DIRS//,/ }" APPLICATION_FILES="${APPLICATION_FILES//,/ }" @@ -555,7 +730,7 @@ __setup_directories() { fi done } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # set user on files/folders __fix_permissions() { change_user="${1:-${SERVICE_USER:-root}}" @@ -580,28 +755,48 @@ __fix_permissions() { fi fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -__get_gid() { grep "^$1:" /etc/group | awk -F ':' '{print $3}' || false; } -__get_uid() { grep "^$1:" /etc/passwd | awk -F ':' '{print $3}' || false; } -__check_for_uid() { cat "/etc/passwd" 2>/dev/null | awk -F ':' '{print $3}' | sort -u | grep -q "^$1$" || false; } -__check_for_guid() { cat "/etc/group" 2>/dev/null | awk -F ':' '{print $3}' | sort -u | grep -q "^$1$" || false; } -__check_for_user() { cat "/etc/passwd" 2>/dev/null | awk -F ':' '{print $1}' | sort -u | grep -q "^$1$" || false; } -__check_for_group() { cat "/etc/group" 2>/dev/null | awk -F ':' '{print $1}' | sort -u | grep -q "^$1$" || false; } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - +__get_gid() { awk -F: -v n="$1" '$1==n {print $3; found=1; exit} END {exit !found}' /etc/group 2>/dev/null; } +__get_uid() { awk -F: -v n="$1" '$1==n {print $3; found=1; exit} END {exit !found}' /etc/passwd 2>/dev/null; } +__check_for_uid() { awk -F: -v n="$1" '$3==n {found=1; exit} END {exit !found}' /etc/passwd 2>/dev/null; } +__check_for_guid() { awk -F: -v n="$1" '$3==n {found=1; exit} END {exit !found}' /etc/group 2>/dev/null; } +__check_for_user() { awk -F: -v n="$1" '$1==n {found=1; exit} END {exit !found}' /etc/passwd 2>/dev/null; } +__check_for_group() { awk -F: -v n="$1" '$1==n {found=1; exit} END {exit !found}' /etc/group 2>/dev/null; } +# - - - - - - - - - - - - - - - - - - - - - - - - - # check if process is already running __proc_check() { - cmd_bin="$(type -P "${1:-$EXEC_CMD_BIN}")" - cmd_name="$(basename "${cmd_bin:-$EXEC_CMD_NAME}")" - if __pgrep "$cmd_bin" || __pgrep "$cmd_name"; then + # Skip process check for one-shot/configuration services + if [ "$SERVICE_USES_PID" = "no" ]; then + return 1 + fi + local cmd_bin cmd_name check_result + cmd_bin="$(type -P "${1:-$EXEC_CMD_BIN}" 2>/dev/null || echo "${1:-$EXEC_CMD_BIN}")" + cmd_name="${cmd_bin:-${1:-$EXEC_CMD_NAME}}"; cmd_name="${cmd_name##*/}" + if [ -z "$cmd_name" ] || [ "$cmd_name" = "." ]; then + return 1 + fi + check_result=1 + if [ -n "$cmd_bin" ] && __pgrep "$cmd_bin" 2>/dev/null; then + check_result=0 + elif [ -n "$cmd_name" ] && __pgrep "$cmd_name" 2>/dev/null; then + check_result=0 + elif [ -f "$SERVICE_PID_FILE" ]; then + local pid_from_file + pid_from_file=$(<"$SERVICE_PID_FILE") 2>/dev/null + if [ -n "$pid_from_file" ] && kill -0 "$pid_from_file" 2>/dev/null; then + check_result=0 + fi + fi + if [ $check_result -eq 0 ]; then SERVICE_IS_RUNNING="yes" - touch "$SERVICE_PID_FILE" + pgrep -x -n "$cmd_name" >"$SERVICE_PID_FILE" 2>/dev/null || true return 0 else return 1 fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __set_user_group_id() { local exitStatus=0 local set_user="${1:-$SERVICE_USER}" @@ -610,22 +805,28 @@ __set_user_group_id() { local random_id="$(__generate_random_uids)" set_uid="$(__get_uid "$set_user" || echo "$set_uid")" set_gid="$(__get_gid "$set_user" || echo "$set_gid")" - grep -shq "^$set_user:" "/etc/passwd" "/etc/group" || return 0 - [ -n "$set_user" ] && [ "$set_user" != "root" ] || return + if ! grep -shq "^$set_user:" "/etc/passwd" "/etc/group"; then + return 0 + fi + if [ -z "$set_user" ] || [ "$set_user" = "root" ]; then + return + fi if grep -shq "^$set_user:" "/etc/passwd" "/etc/group"; then if __check_for_guid "$set_gid"; then - groupmod -g "${set_gid}" $set_user 2>/dev/stderr | tee -p -a "/data/logs/init.txt" >/dev/null && chown -Rf ":$set_gid" + groupmod -g "${set_gid}" $set_user 2>/dev/stderr | tee -p -a "/data/logs/init.txt" >/dev/null fi if __check_for_uid "$set_uid"; then - usermod -u "${set_uid}" -g "${set_gid}" $set_user 2>/dev/stderr | tee -p -a "/data/logs/init.txt" >/dev/null && chown -Rf $set_uid:$set_gid + usermod -u "${set_uid}" -g "${set_gid}" $set_user 2>/dev/stderr | tee -p -a "/data/logs/init.txt" >/dev/null fi fi export SERVICE_UID="$set_uid" export SERVICE_GID="$set_gid" } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __create_service_user() { local exitStatus=0 + local max_attempts=100 + local attempt=0 local create_user="${1:-$SERVICE_USER}" local create_group="${2:-${SERVICE_GROUP:-$create_user}}" local create_home_dir="${3:-$WORK_DIR}" @@ -633,61 +834,128 @@ __create_service_user() { local create_gid="${5:-${SERVICE_GID:-$USER_GID}}" local random_id="$(__generate_random_uids)" local create_home_dir="${create_home_dir:-/home/$create_user}" - grep -shq "^$create_user:" "/etc/passwd" && grep -shq "^$create_group:" "/etc/group" && return - [ "$create_user" = "root" ] && [ "$create_group" = "root" ] && return 0 - if [ "$RUNAS_USER" != "root" ] && [ "$RUNAS_USER" != "" ]; then + local log_file="/data/logs/init.txt" + # Ensure log directory exists + [ -d "$(dirname "$log_file")" ] || mkdir -p "$(dirname "$log_file")" 2>/dev/null + # Validate that we have at least a user or group to create + if [ -z "$create_user" ] && [ -z "$create_group" ]; then + echo "No user or group specified to create" >&2 + return 0 + fi + # Validate user/group name format (alphanumeric, underscore, hyphen; must start with letter or underscore) + if [ -n "$create_user" ] && [[ ! "$create_user" =~ ^[a-z_][a-z0-9_-]*$ ]]; then + echo "Error: Invalid username format '$create_user' - must start with letter/underscore, contain only lowercase alphanumeric, underscore, or hyphen" >&2 + return 1 + fi + if [ -n "$create_group" ] && [[ ! "$create_group" =~ ^[a-z_][a-z0-9_-]*$ ]]; then + echo "Error: Invalid group name format '$create_group' - must start with letter/underscore, contain only lowercase alphanumeric, underscore, or hyphen" >&2 + return 1 + fi + # Check if user and group already exist + if grep -shq "^$create_user:" "/etc/passwd" && grep -shq "^$create_group:" "/etc/group"; then + return 0 + fi + # Root user/group - nothing to create + if [ "$create_user" = "root" ] && [ "$create_group" = "root" ]; then + return 0 + fi + # Override with RUNAS_USER if specified and not root + if [ -n "$RUNAS_USER" ] && [ "$RUNAS_USER" != "root" ]; then create_user="$RUNAS_USER" create_group="$RUNAS_USER" create_uid="${create_uid:-1000}" create_gid="${create_gid:-1000}" fi - create_uid="$(__get_uid "$create_user" || echo "$create_uid")" - create_gid="$(__get_gid "$create_user" || echo "$create_gid")" - [ -n "$create_uid" ] && [ "$create_uid" != "0" ] || create_uid="$random_id" - [ -n "$create_gid" ] && [ "$create_gid" != "0" ] || create_gid="$random_id" - while :; do - if __check_for_uid "$create_uid" && __check_for_guid "$create_gid"; then - create_uid=$(($random_id + 1)) - create_gid="$create_uid" - else - break + # Get existing UID/GID or use provided values + create_uid="$(__get_uid "$create_user" 2>/dev/null || echo "$create_uid")" + create_gid="$(__get_gid "$create_user" 2>/dev/null || echo "$create_gid")" + # Ensure we have valid non-root UID/GID + if [ -z "$create_uid" ] || [ "$create_uid" = "0" ]; then + create_uid="$random_id" + fi + if [ -z "$create_gid" ] || [ "$create_gid" = "0" ]; then + create_gid="$random_id" + fi + # Validate UID/GID are numeric and within valid range + if [[ ! "$create_uid" =~ ^[0-9]+$ ]] || [ "$create_uid" -lt 1 ] || [ "$create_uid" -gt 65534 ]; then + echo "Error: Invalid UID '$create_uid' - must be a number between 1 and 65534" >&2 + return 1 + fi + if [[ ! "$create_gid" =~ ^[0-9]+$ ]] || [ "$create_gid" -lt 1 ] || [ "$create_gid" -gt 65534 ]; then + echo "Error: Invalid GID '$create_gid' - must be a number between 1 and 65534" >&2 + return 1 + fi + # Find available UID/GID if current ones are taken (with loop protection) + while __check_for_uid "$create_uid" || __check_for_guid "$create_gid"; do + attempt=$((attempt + 1)) + if [ $attempt -ge $max_attempts ]; then + echo "Error: Could not find available UID/GID after $max_attempts attempts" >&2 + return 1 fi + random_id=$((random_id + 1)) + create_uid="$random_id" + create_gid="$random_id" done - if ! __check_for_group "$create_group"; then - echo "creating system group $create_group" - groupadd --force --system -g $create_gid $create_group 2>/dev/stderr | tee -p -a "/data/logs/init.txt" >/dev/null + # Create group if needed + if [ -n "$create_group" ] && ! __check_for_group "$create_group"; then + echo "Creating system group '$create_group' with GID $create_gid" + if ! groupadd --force --system -g "$create_gid" "$create_group" 2>&1 | tee -a "$log_file"; then + echo "Error: Failed to create group '$create_group'" >&2 + exitStatus=$((exitStatus + 1)) + elif ! grep -shq "^$create_group:" "/etc/group"; then + echo "Error: Group '$create_group' not found in /etc/group after creation" >&2 + exitStatus=$((exitStatus + 1)) + fi fi - if ! __check_for_user "$create_user"; then - echo "creating system user $create_user" - useradd --system -u $create_uid -g $create_group -c "Account for $create_user" -d "$create_home_dir" -s /bin/false $create_user 2>/dev/stderr | tee -p -a "/data/logs/init.txt" >/dev/null + # Create user if needed (only if group creation succeeded) + if [ $exitStatus -eq 0 ] && [ -n "$create_user" ] && ! __check_for_user "$create_user"; then + echo "Creating system user '$create_user' with UID $create_uid" + if ! useradd --system --uid "$create_uid" --gid "$create_group" --comment "Account for $create_user" --home-dir "$create_home_dir" --shell /bin/false "$create_user" 2>&1 | tee -a "$log_file"; then + echo "Error: Failed to create user '$create_user'" >&2 + exitStatus=$((exitStatus + 1)) + elif ! grep -shq "^$create_user:" "/etc/passwd"; then + echo "Error: User '$create_user' not found in /etc/passwd after creation" >&2 + exitStatus=$((exitStatus + 1)) + fi fi - grep -shq "$create_group" "/etc/group" || exitStatus=$((exitStatus + 1)) - grep -shq "$create_user" "/etc/passwd" || exitStatus=$((exitCode + 1)) - if [ $exitStatus -eq 0 ]; then + # Setup user environment if creation succeeded + if [ $exitStatus -eq 0 ] && [ -n "$create_group" ] && [ -n "$create_user" ]; then export WORK_DIR="${create_home_dir:-}" if [ -n "$WORK_DIR" ]; then - [ -d "$WORK_DIR" ] || mkdir -p "$WORK_DIR" - [ -d "/etc/.skel" ] && cp -Rf /etc/.skel/. "$WORK_DIR/" + if [ ! -d "$WORK_DIR" ]; then + if ! mkdir -p "$WORK_DIR" 2>/dev/null; then + echo "Warning: Failed to create home directory '$WORK_DIR'" >&2 + fi + fi + if [ -d "/etc/.skel" ] && [ -d "$WORK_DIR" ]; then + cp -Rf /etc/.skel/. "$WORK_DIR/" 2>/dev/null || echo "Warning: Failed to copy skeleton files to '$WORK_DIR'" >&2 + fi fi - if [ -d "/etc/sudoers.d" ] && [ ! -f "/etc/sudoers.d/$create_user" ]; then - echo "$create_user ALL=(ALL) NOPASSWD: ALL" >"/etc/sudoers.d/$create_user" - elif [ -f "/etc/sudoers" ] && ! grep -qs "$create_user" "/etc/sudoers"; then - echo "$create_user ALL=(ALL) NOPASSWD: ALL" >"/etc/sudoers" + # Setup sudo access + if [ -d "/etc/sudoers.d" ]; then + if [ ! -f "/etc/sudoers.d/$create_user" ]; then + echo "$create_user ALL=(ALL) NOPASSWD: ALL" >"/etc/sudoers.d/$create_user" 2>/dev/null || echo "Warning: Failed to create sudoers file for '$create_user'" >&2 + chmod 0440 "/etc/sudoers.d/$create_user" 2>/dev/null + fi + elif [ -f "/etc/sudoers" ] && ! grep -qs "^$create_user " "/etc/sudoers"; then + echo "$create_user ALL=(ALL) NOPASSWD: ALL" >>"/etc/sudoers" 2>/dev/null || echo "Warning: Failed to add '$create_user' to sudoers" >&2 fi - export SERVICE_UID="$create_uid" - export SERVICE_GID="$create_gid" - export SERVICE_USER="$create_user" - export SERVICE_GROUP="$create_group" + SERVICE_UID="$create_uid" + SERVICE_GID="$create_gid" + SERVICE_USER="$create_user" + SERVICE_GROUP="$create_group" else - export USER_UID=0 - export USER_GID=0 - export SERVICE_USER=root - export SERVICE_GROUP=root + echo "Warning: Falling back to root user due to creation errors" >&2 + SERVICE_UID=0 + SERVICE_GID=0 + SERVICE_USER=root + SERVICE_GROUP=root exitStatus=2 fi + export SERVICE_UID SERVICE_GID SERVICE_USER SERVICE_GROUP return $exitStatus } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __create_env_file() { local dir="" local envStatus=0 @@ -698,28 +966,26 @@ __create_env_file() { dir="$(dirname "$create_env")" [ -d "$dir" ] || mkdir -p "$dir" if [ -n "$create_env" ] && [ ! -f "$create_env" ]; then - cat </dev/null -$(<"$sample_file") -EOF + cp -f "$sample_file" "$create_env" fi [ -f "$create_env" ] || envStatus=$((1 + envStatus)) done - rm -f "$sample_file" + [ "$envStatus" -eq 0 ] && rm -f "$sample_file" return $envStatus } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __exec_command() { - local bin="" local arg=("$@") - local exitCode="0" + local exitCode=0 local cmdExec="${arg:-}" local pre_exec="--login -c" - local shell="$(type -P bash 2>/dev/null || type -P dash 2>/dev/null || type -P ash 2>/dev/null || type -P sh 2>/dev/null)" - bin="$(echo "${arg[*]}" | tr ' ' '\n' | grep -v '^$' | head -n1 | sed 's| ||g' || echo 'bash')" + local shell bin prog + shell=$(type -P bash || type -P dash || type -P ash || type -P sh) 2>/dev/null + bin="${arg[0]:-bash}" prog="$(type -P "$bin" 2>/dev/null || echo "$bin")" - if type -t $bin >/dev/null 2>&1; then + if type -t "$bin" &>/dev/null; then echo "${exec_message:-Executing command: $cmdExec}" - eval $shell $pre_exec "$cmdExec" || exitCode=1 + "$shell" $pre_exec "$cmdExec" exitCode=$? elif [ -f "$prog" ]; then echo "$prog is not executable" @@ -730,19 +996,28 @@ __exec_command() { fi return $exitCode } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # Setup the server init scripts __start_init_scripts() { [ "$1" = " " ] && shift 1 - [ "$DEBUGGER" = "on" ] && echo "Enabling debugging" && set -o pipefail -x$DEBUGGER_OPTIONS || set -o pipefail + if [ "$DEBUGGER" = "on" ]; then + echo "Enabling debugging" + set -o pipefail + [ -n "$DEBUGGER_OPTIONS" ] && set -"$DEBUGGER_OPTIONS" + else + set -o pipefail + fi local retPID="" local basename="" local init_pids="" local retstatus="0" local initStatus="0" local critical_failures="0" + local pidFile="/run/.start_init_scripts.pid" local init_dir="${1:-/usr/local/etc/docker/init.d}" - local init_count="$(ls -A "$init_dir"/* 2>/dev/null | grep -v '\.sample' | wc -l)" + local init_files=("$init_dir"/*.sh) + local init_count=0 + [ -e "${init_files[0]}" ] && init_count=${#init_files[@]} local exit_on_failure="${EXIT_ON_SERVICE_FAILURE:-true}" # Clean stale PID files from previous runs @@ -751,15 +1026,18 @@ __start_init_scripts() { rm -f /run/*.pid /run/init.d/*.pid 2>/dev/null || true fi - touch /run/.start_init_scripts.pid + touch "$pidFile" if [ "$init_count" -eq 0 ] || [ ! -d "$init_dir" ]; then mkdir -p "/data/logs/init" while :; do echo "Running: $(date)" >"/data/logs/init/keep_alive" && sleep 3600; done & else if [ -d "$init_dir" ]; then - [ -f "$init_dir/service.sample" ] && __rm "$init_dir"/*.sample - chmod -Rf 755 "$init_dir"/*.sh + local sample + for sample in "$init_dir"/*.sample; do + [ -e "$sample" ] && __rm "$sample" + done + (shopt -s nullglob; chmod -Rf 755 "$init_dir"/*.sh 2>/dev/null || true) echo "🚀 Starting container services initialization" echo "📂 Init directory: $init_dir" @@ -769,69 +1047,68 @@ __start_init_scripts() { for init in "$init_dir"/*.sh; do if [ -x "$init" ]; then - name="$(basename "$init")" - service="$(printf '%s' "$name" | sed 's/^[^-]*-//;s|.sh$||g')" - __service_banner "🔧" "Executing service script:" "$(basename "$init")" - # Execute the init script and capture the exit code - if source "$init"; then + touch "$pidFile" + name="${init##*/}" + service="${name#*-}"; service="${service%.sh}" + __service_banner "🔧" "Executing service script:" "${init##*/}" + # Execute the init script and capture the exit code (subshell isolates exit calls) + if ( source "$init" ); then # Check if service was disabled first if [ -n "$SERVICE_DISABLED" ]; then initStatus="0" __service_banner "🚫" "Service $service is disabled -" "skipping" unset SERVICE_DISABLED + # Continue to next service + elif [ "$CONTAINER_INIT" = "yes" ]; then + initStatus="0" + __service_banner "✅" "Service $service completed successfully -" "configuration service" else - sleep 2 + # Allow some time for service to initialize + sleep 1 # Check for service success indicators local expected_pid_file="/run/init.d/$service.pid" + set +e + # Check if this is a configuration service (no daemon process expected) if [ "$SERVICE_USES_PID" = "no" ]; then - # Service doesn't use PID files - check if expected PID file exists or assume success - if [ -f "$expected_pid_file" ]; then - retPID="$(cat "$expected_pid_file" 2>/dev/null || echo "0")" - initStatus="0" - __service_banner "✅" "Service $service started successfully -" "PID file" - else - initStatus="0" - __service_banner "✅" "Service $service started successfully -" "no PID tracking" - fi + # Configuration service - no daemon process expected + initStatus="0" + __service_banner "✅" "Service $service completed successfully -" "configuration service" else # Service uses PID tracking - verify actual running processes - set +e # Temporarily disable exit on error retPID="" - - # First, try to find actual running process with various name patterns - for name_variant in "$service" "${service}84" "${service}d" "$(echo "$service" | sed 's/-//g')" "$(echo "$service" | tr -d '-')"; do + local found_process="" + # Try multiple name variants to find the process + for name_variant in "$service" "${service}d" "${service//-/}"; do if [ -z "$retPID" ]; then retPID=$(__get_pid "$name_variant" 2>/dev/null || echo "") - [ -n "$retPID" ] && found_process="$name_variant" && break + if [ -n "$retPID" ] && [ "$retPID" != "0" ]; then + found_process="$name_variant" + break + fi fi done - - set -e # Re-enable exit on error - if [ -n "$retPID" ] && [ "$retPID" != "0" ]; then # Found actual running process initStatus="0" __service_banner "✅" "Service $service started successfully -" "PID: ${retPID} ($found_process)" elif [ -f "$expected_pid_file" ]; then # No running process but PID file exists - verify PID is valid - file_pid="$(cat "$expected_pid_file" 2>/dev/null || echo "")" + file_pid=$(<"$expected_pid_file") 2>/dev/null if [ -n "$file_pid" ] && kill -0 "$file_pid" 2>/dev/null; then initStatus="0" __service_banner "✅" "Service $service started successfully -" "PID: $file_pid (from file)" - elif [ -n "$file_pid" ]; then - initStatus="1" - critical_failures=$((critical_failures + 1)) - __service_banner "⚠️" "Service $service has stale PID file -" "process $file_pid not running" else + # PID file exists but process isn't running - treat as warning, not failure initStatus="0" - __service_banner "✅" "Service $service completed initialization -" "no process tracking" + __service_banner "⚠️" "Service $service may not be running -" "no process found (non-critical)" fi else - # No process and no PID file - this is likely a configuration-only service + # No process and no PID file - likely a configuration-only service initStatus="0" __service_banner "✅" "Service $service completed successfully -" "configuration service" fi fi + set -e fi else initStatus="1" @@ -844,22 +1121,26 @@ __start_init_scripts() { done # Summary + echo "" if [ $critical_failures -gt 0 ]; then - echo "⚠️ Warning: $critical_failures service(s) failed to start" - if [ "$exit_on_failure" = "true" ] && [ $critical_failures -ge 1 ]; then - echo "❌ Exiting due to critical service failures" + echo "⚠️ Warning: $critical_failures critical service(s) reported failures" + if [ "$exit_on_failure" = "true" ] && [ $critical_failures -ge 2 ]; then + echo "❌ Exiting due to multiple critical service failures (threshold: 2)" return 1 + else + echo "ℹ️ Continuing with $critical_failures failure(s) - container may still be functional" fi else - echo "✅ All services started successfully" + echo "✅ All service initializations completed successfully" fi + echo "" fi fi printf '%s\n' "$SERVICE_NAME started on $(date)" >"/data/logs/start.log" return $retstatus } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __setup_mta() { [ -d "/etc/ssmtp" ] || [ -d "/etc/postfix" ] || return if [ ! -d "/config/ssmtp" ] || [ ! -d "/config/postfix" ]; then @@ -871,14 +1152,14 @@ __setup_mta() { local local_hostname="${FULL_DOMAIN_NAME:-}" local account_user="${SERVER_ADMIN//@*/}" local account_domain="${EMAIL_DOMAIN//*@/}" - echo "$EMAIL_RELAY" | grep '[0-9][0-9]' || relay_port="465" + [[ $EMAIL_RELAY == *[0-9][0-9]* ]] || relay_port="465" ################# sSMTP relay setup - if [ -n "$(type -P 'ssmtp')" ]; then + if command -v ssmtp &>/dev/null; then [ -d "/config/ssmtp" ] || mkdir -p "/config/ssmtp" [ -f "/etc/ssmtp/ssmtp.conf" ] && __rm "/etc/ssmtp/ssmtp.conf" symlink_files="$(__find_file_relative "/config/ssmtp")" if [ ! -f "/config/ssmtp/ssmtp.conf" ]; then - cat </dev/null + cat >"/config/ssmtp/ssmtp.conf" </dev/null; then [ -d "/etc/postfix" ] || mkdir -p "/etc/postfix" [ -d "/config/postfix" ] || mkdir -p "/config/postfix" [ -f "/etc/postfix/main.cf" ] && __rm "/etc/postfix/main.cf" symlink_files="$(__find_file_relative "/config/postfix")" if [ ! -f "/config/postfix/main.cf" ]; then - cat </dev/null + cat >"/config/postfix/main.cf" </dev/null - postmap "/config/mydomains.pcre" "/config/mydomains" "/config/virtual" &>/dev/null + postmap "/config/postfix/aliases" "/config/postfix/mynetworks" "/config/postfix/transport" &>/dev/null + postmap "/config/postfix/mydomains.pcre" "/config/postfix/mydomains" "/config/postfix/virtual" &>/dev/null fi if [ -f "/etc/postfix/main.cf" ] && [ ! -f "/run/init.d/postfix.pid" ]; then SERVICES_LIST+="postfix " @@ -966,7 +1247,7 @@ EOF [ -f "/root/dead.letter" ] && __rm "/root/dead.letter" return $exitCode } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __initialize_web_health() { local www_dir="${1:-${WWW_ROOT_DIR:-/usr/local/share/httpd/default}}" if [ -d "$www_dir" ]; then @@ -975,7 +1256,7 @@ __initialize_web_health() { __find_replace "REPLACE_LAST_UPDATED_ON_MESSAGE" "${LAST_UPDATED_ON_MESSAGE:-$(date +'Last updated on: %Y-%m-%d at %H:%M:%S')}" "/usr/local/share/httpd" fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # file_dir __initialize_replace_variables() { local set_dir="" get_dir="$*" @@ -1018,7 +1299,7 @@ __initialize_replace_variables() { mkdir -p "${TMP_DIR:-/tmp/$SERVICE_NAME}" "${RUN_DIR:-/run/$SERVICE_NAME}" "${LOG_DIR:-/data/logs/$SERVICE_NAME}" chmod -f 777 "${TMP_DIR:-/tmp/$SERVICE_NAME}" "${RUN_DIR:-/run/$SERVICE_NAME}" "${LOG_DIR:-/data/logs/$SERVICE_NAME}" } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __initialize_database() { [ "$IS_DATABASE_SERVICE" = "yes" ] || [ "$USES_DATABASE_SERVICE" = "yes" ] || return 0 local dir="${1:-$ETC_DIR}" @@ -1036,7 +1317,7 @@ __initialize_database() { __find_replace "REPLACE_DATABASE_ROOT_PASS" "$db_admin_pass" "$dir" __find_replace "REPLACE_DATABASE_NAME" "$DATABASE_NAME" "$dir" __find_replace "REPLACE_DATABASE_DIR" "$DATABASE_DIR" "$dir" - if echo "$dir" | grep -q '^/etc'; then + if [[ "$dir" == "/etc"* ]]; then __find_replace "REPLACE_USER_NAME" "$db_normal_user" "/etc" __find_replace "REPLACE_USER_PASS" "$db_normal_pass" "/etc" __find_replace "REPLACE_DATABASE_USER" "$db_normal_user" "/etc" @@ -1049,7 +1330,7 @@ __initialize_database() { __find_replace "REPLACE_DATABASE_DIR" "$DATABASE_DIR" "/etc" fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __initialize_db_users() { [ "$IS_DATABASE_SERVICE" = "yes" ] || [ "$USES_DATABASE_SERVICE" = "yes" ] || return 0 db_normal_user="${DATABASE_USER_NORMAL:-$user_name}" @@ -1062,15 +1343,15 @@ __initialize_db_users() { export DATABASE_PASS_ROOT="$db_admin_pass" export db_normal_user db_normal_pass db_admin_user db_admin_pass } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __initialize_system_etc() { local conf_dir="$1" local dir="" - local file=() + local files="" local directories="" if [ -n "$conf_dir" ] && [ -e "$conf_dir" ]; then - files="$(find "$conf_dir"/* -not -path '*/env/*' -type f 2>/dev/null | sed 's|'/config/'||g' | sort -u | grep -v '^$' | grep '.' || false)" - directories="$(find "$conf_dir"/* -not -path '*/env/*' -type d 2>/dev/null | sed 's|'/config/'||g' | sort -u | grep -v '^$' | grep '.' || false)" + files=$(find "$conf_dir"/* -not -path '*/env/*' -type f 2>/dev/null | sort -u | sed 's|/config/||') + directories=$(find "$conf_dir"/* -not -path '*/env/*' -type d 2>/dev/null | sort -u | sed 's|/config/||') echo "Copying config files to system: $conf_dir > /etc/${conf_dir//\/config\//}" if [ -n "$directories" ]; then for d in $directories; do @@ -1089,7 +1370,7 @@ __initialize_system_etc() { done fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __initialize_custom_bin_dir() { local SET_USR_BIN="" [ -d "/data/bin" ] && SET_USR_BIN+="$(__find /data/bin f) " @@ -1098,7 +1379,7 @@ __initialize_custom_bin_dir() { echo "Setting up bin $SET_USR_BIN > $LOCAL_BIN_DIR" for create_bin_template in $SET_USR_BIN; do if [ -n "$create_bin_template" ]; then - create_bin_name="$(basename "$create_bin_template")" + create_bin_name="${create_bin_template##*/}" if [ -e "$create_bin_template" ]; then ln -sf "$create_bin_template" "$LOCAL_BIN_DIR/$create_bin_name" fi @@ -1107,53 +1388,88 @@ __initialize_custom_bin_dir() { unset create_bin_template create_bin_name SET_USR_BIN fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __initialize_default_templates() { + local errors=0 if [ -n "$DEFAULT_TEMPLATE_DIR" ]; then - if [ "$CONFIG_DIR_INITIALIZED" = "false" ] && [ -d "/config" ]; then - echo "Copying default config files $DEFAULT_TEMPLATE_DIR > /config" + if [ "$CONFIG_DIR_INITIALIZED" = "no" ] && [ -d "/config" ]; then + __log_info "Copying default config files $DEFAULT_TEMPLATE_DIR > /config" + if [ ! -d "$DEFAULT_TEMPLATE_DIR" ]; then + __log_warn "Template directory not found: $DEFAULT_TEMPLATE_DIR" + return 0 + fi for create_config_template in "$DEFAULT_TEMPLATE_DIR"/*; do - if [ -n "$create_config_template" ]; then - create_template_name="$(basename "$create_config_template")" + if [ -e "$create_config_template" ]; then + create_template_name="${create_config_template##*/}" if [ -d "$create_config_template" ]; then - mkdir -p "/config/$create_template_name/" - __is_dir_empty "/config/$create_template_name" && cp -Rf "$create_config_template/." "/config/$create_template_name/" 2>/dev/null - elif [ -e "$create_config_template" ]; then - [ -e "/config/$create_template_name" ] || cp -Rf "$create_config_template" "/config/$create_template_name" 2>/dev/null + mkdir -p "/config/$create_template_name/" || errors=$((errors + 1)) + if __is_dir_empty "/config/$create_template_name"; then + if ! cp -Rf "$create_config_template/." "/config/$create_template_name/" 2>/dev/null; then + __log_warn "Failed to copy template directory: $create_template_name" + errors=$((errors + 1)) + fi + fi + elif [ -f "$create_config_template" ]; then + if [ ! -e "/config/$create_template_name" ]; then + if ! cp -Rf "$create_config_template" "/config/$create_template_name" 2>/dev/null; then + __log_warn "Failed to copy template file: $create_template_name" + errors=$((errors + 1)) + fi + fi fi fi done unset create_config_template create_template_name + __log_debug "Template initialization completed with $errors errors" fi fi + return 0 } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __initialize_config_dir() { + local errors=0 if [ -n "$DEFAULT_CONF_DIR" ]; then - if [ "$CONFIG_DIR_INITIALIZED" = "false" ] && [ -d "/config" ]; then - echo "Copying custom config files: $DEFAULT_CONF_DIR > /config" + if [ "$CONFIG_DIR_INITIALIZED" = "no" ] && [ -d "/config" ]; then + __log_info "Copying custom config files: $DEFAULT_CONF_DIR > /config" + if [ ! -d "$DEFAULT_CONF_DIR" ]; then + __log_warn "Config directory not found: $DEFAULT_CONF_DIR" + return 0 + fi for create_config_template in "$DEFAULT_CONF_DIR"/*; do - create_config_name="$(basename "$create_config_template")" - if [ -n "$create_config_template" ]; then + if [ -e "$create_config_template" ]; then + create_config_name="${create_config_template##*/}" if [ -d "$create_config_template" ]; then - mkdir -p "/config/$create_config_name" - __is_dir_empty "/config/$create_config_name" && cp -Rf "$create_config_template/." "/config/$create_config_name/" 2>/dev/null - elif [ -e "$create_config_template" ]; then - [ -e "/config/$create_config_name" ] || cp -Rf "$create_config_template" "/config/$create_config_name" 2>/dev/null + mkdir -p "/config/$create_config_name" || errors=$((errors + 1)) + if __is_dir_empty "/config/$create_config_name"; then + if ! cp -Rf "$create_config_template/." "/config/$create_config_name/" 2>/dev/null; then + __log_warn "Failed to copy config directory: $create_config_name" + errors=$((errors + 1)) + fi + fi + elif [ -f "$create_config_template" ]; then + if [ ! -e "/config/$create_config_name" ]; then + if ! cp -Rf "$create_config_template" "/config/$create_config_name" 2>/dev/null; then + __log_warn "Failed to copy config file: $create_config_name" + errors=$((errors + 1)) + fi + fi fi fi done unset create_config_template create_config_name + __log_debug "Config initialization completed with $errors errors" fi fi + return 0 } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __initialize_data_dir() { + [ "$DATA_DIR_INITIALIZED" = "no" ] || return 0 if [ -d "/data" ]; then - if [ "$DATA_DIR_INITIALIZED" = "false" ] && [ -n "$DEFAULT_DATA_DIR" ]; then - echo "Copying data files $DEFAULT_DATA_DIR > /data" + if [ -n "$DEFAULT_DATA_DIR" ]; then + __log_info "Copying data files $DEFAULT_DATA_DIR > /data" for create_data_template in "$DEFAULT_DATA_DIR"/*; do - create_data_name="$(basename "$create_data_template")" + create_data_name="${create_data_template##*/}" if [ -n "$create_data_template" ]; then if [ -d "$create_data_template" ]; then mkdir -p "/data/$create_data_name" @@ -1163,35 +1479,43 @@ __initialize_data_dir() { fi fi done - unset create_template + unset create_data_template fi fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __initialize_www_root() { local WWW_INIT="" local WWW_TEMPLATE="" [ -d "/usr/local/share/httpd/default" ] && WWW_TEMPLATE="/usr/local/share/httpd/default" [ "$WWW_ROOT_DIR" = "/app" ] && WWW_INIT="${WWW_INIT:-true}" [ "$WWW_ROOT_DIR" = "/data/htdocs" ] && WWW_INIT="${WWW_INIT:-true}" - __is_dir_empty "$WWW_ROOT_DIR/" && WWW_INIT="true" || WWW_INIT="false" + if __is_dir_empty "$WWW_ROOT_DIR/"; then + WWW_INIT="true" + else + WWW_INIT="false" + fi if [ "$WWW_INIT" = "true" ] && [ -d "$WWW_TEMPLATE" ]; then cp -Rf "$DEFAULT_DATA_DIR/data/htdocs/." "$WWW_ROOT_DIR/" 2>/dev/null fi __initialize_web_health "$WWW_ROOT_DIR" } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __is_htdocs_mounted() { WWW_ROOT_DIR="${WWW_ROOT_DIR:-/data/htdocs}" [ -n "$ENV_WWW_ROOT_DIR" ] && WWW_ROOT_DIR="$ENV_WWW_ROOT_DIR" - [ -n "$IMPORT_FROM_GIT" ] && echo "$IMPORT_FROM_GIT" | grep -qE 'https://|http://|git://|ssh://' || unset IMPORT_FROM_GIT - if [ -n "$IMPORT_FROM_GIT" ] && [ "$(command -v "git" 2>/dev/null)" ]; then + if [ -n "$IMPORT_FROM_GIT" ]; then + if [[ ! "$IMPORT_FROM_GIT" =~ (https://|http://|git://|ssh://) ]]; then + unset IMPORT_FROM_GIT + fi + fi + if [ -n "$IMPORT_FROM_GIT" ] && command -v git &>/dev/null; then if __is_dir_empty "$WWW_ROOT_DIR"; then echo "Importing project from $IMPORT_FROM_GIT to $WWW_ROOT_DIR" git clone -q "$IMPORT_FROM_GIT" "$WWW_ROOT_DIR" elif [ -d "$WWW_ROOT_DIR" ]; then echo "Updating the project in $WWW_ROOT_DIR" - git -C pull -q "$WWW_ROOT_DIR" + git -C "$WWW_ROOT_DIR" pull -q fi elif [ -d "/app" ]; then WWW_ROOT_DIR="/app" @@ -1207,7 +1531,7 @@ __is_htdocs_mounted() { [ -d "$WWW_ROOT_DIR" ] || mkdir -p "$WWW_ROOT_DIR" export WWW_ROOT_DIR="${WWW_ROOT_DIR:-/usr/local/share/httpd/default}" } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __initialize_ssl_certs() { [ "$SSL_ENABLED" = "yes" ] && __certbot if [ -d "/config/letsencrypt" ]; then @@ -1234,20 +1558,20 @@ __initialize_ssl_certs() { fi type update-ca-certificates &>/dev/null && update-ca-certificates &>/dev/null } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __start_php_dev_server() { if [ "$2" = "yes" ]; then if [ -d "/usr/local/share/httpd" ]; then find "/usr/local/share/httpd" -type f -not -path '.git*' -iname '*.php' -exec sed -i 's|[<].*SERVER_ADDR.*[>]|'${CONTAINER_IP4_ADDRESS:-127.0.0.1}'|g' {} \; 2>/dev/null php -S 0.0.0.0:$PHP_DEV_SERVER_PORT -t "/usr/local/share/httpd" fi - if ! echo "$1" | grep -q "^/usr/local/share/httpd"; then + if [[ "$1" != "/usr/local/share/httpd"* ]]; then find "$1" -type f -not -path '.git*' -iname '*.php' -exec sed -i 's|[<].*SERVER_ADDR.*[>]|'${CONTAINER_IP4_ADDRESS:-127.0.0.1}'|g' {} \; 2>/dev/null php -S 0.0.0.0:$PHP_DEV_SERVER_PORT -t "$1" fi fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __check_service() { if [ "$1" = "check" ]; then shift $# @@ -1255,35 +1579,52 @@ __check_service() { exit $? fi } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - __switch_to_user() { - if [ "$RUNAS_USER" = "root" ]; then + # Use SERVICE_USER if set, otherwise fall back to RUNAS_USER + local switch_user="${SERVICE_USER:-$RUNAS_USER}" + if [ "$switch_user" = "root" ]; then su_exec="" su_cmd() { eval "$@" || return 1; } - elif [ "$(builtin type -P gosu)" ]; then - su_exec="gosu $RUNAS_USER" + elif command -v gosu &>/dev/null; then + su_exec="gosu $switch_user" su_cmd() { $su_exec "$@" || return 1; } - elif [ "$(builtin type -P runuser)" ]; then - su_exec="runuser -u $RUNAS_USER" + elif command -v runuser &>/dev/null; then + su_exec="runuser -u $switch_user" su_cmd() { $su_exec "$@" || return 1; } - elif [ "$(builtin type -P sudo)" ]; then - su_exec="sudo -u $RUNAS_USER" + elif command -v sudo &>/dev/null; then + su_exec="sudo -u $switch_user" su_cmd() { $su_exec "$@" || return 1; } - elif [ "$(builtin type -P su)" ]; then - su_exec="su -s /bin/sh - $RUNAS_USER" + elif command -v su &>/dev/null; then + su_exec="su -s /bin/sh - $switch_user" su_cmd() { $su_exec -c "$@" || return 1; } else su_exec="" - su_cmd() { echo "Can not switch to $RUNAS_USER: attempting to run as root" && eval "$@" || return 1; } + su_cmd() { + echo "Can not switch to $switch_user: attempting to run as root" + if ! eval "$@"; then + return 1 + fi + } fi export su_exec } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # usage backup "days" "hours" __backup() { local dirs="" backup_dir backup_name backup_exclude runTime cronTime maxDays - test -n "$1" && test -z "${1//[0-9]/}" && maxDays="$1" && shift 1 || maxDays="7" - test -n "$1" && test -z "${1//[0-9]/}" && cronTime="$1" && shift 1 || cronTime="" + if test -n "$1" && test -z "${1//[0-9]/}"; then + maxDays="$1" + shift 1 + else + maxDays="7" + fi + if test -n "$1" && test -z "${1//[0-9]/}"; then + cronTime="$1" + shift 1 + else + cronTime="" + fi local exitCodeP=0 local exitStatus=0 local pidFile="/run/.backup.pid" @@ -1300,8 +1641,13 @@ __backup() { [ -z "$dirs" ] && echo "BACKUP_DIR is unset" >&2 && return 1 [ -f "$pidFile" ] && echo "A backup job is already running" >&2 && return 1 echo "$$" >"$pidFile" + trap "rm -f '$pidFile'" EXIT INT TERM echo "Starting backup in $(date)" >>"$logDir/$CONTAINER_NAME" - tar --exclude $backup_exclude cfvz "$backup_dir/$backup_name" $dirs 2>/dev/stderr >>"$logDir/$CONTAINER_NAME" || exitCodeP=1 + local tar_excludes=() + for excl in $backup_exclude; do + tar_excludes+=("--exclude=$excl") + done + tar "${tar_excludes[@]}" -cfvz "$backup_dir/$backup_name" $dirs 2>/dev/stderr >>"$logDir/$CONTAINER_NAME" || exitCodeP=1 if [ $exitCodeP -eq 0 ]; then echo "Backup has completed and saved to: $backup_dir/$backup_name" printf '%s\n\n' "Backup has completed on $(date)" >>"$logDir/$CONTAINER_NAME" @@ -1312,43 +1658,47 @@ __backup() { exitStatus=1 fi [ -f "$pidFile" ] && __rm "$pidFile" - [ -n "$maxDays" ] && find "$BACKUP_DIR"* -mtime +$maxDays -exec rm -Rf {} \; >/dev/null 2>&1 - [ -n "$cronTime" ] && runTime=$((cronTime * 3600)) || return $exitStatus + [ -n "$maxDays" ] && find "$BACKUP_DIR" -mtime +"$maxDays" -exec rm -Rf {} \; >/dev/null 2>&1 + if [ -n "$cronTime" ]; then + runTime=$((cronTime * 3600)) + else + return $exitStatus + fi sleep $runTime && __backup "$maxDays" "$cronTime" } -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # set variables from function calls export INIT_DATE="${INIT_DATE:-$(date)}" export START_SERVICES="${START_SERVICES:-yes}" export ENTRYPOINT_MESSAGE="${ENTRYPOINT_MESSAGE:-yes}" export ENTRYPOINT_FIRST_RUN="${ENTRYPOINT_FIRST_RUN:-yes}" -export DATA_DIR_INITIALIZED="${DATA_DIR_INITIALIZED:-false}" -export CONFIG_DIR_INITIALIZED="${CONFIG_DIR_INITIALIZED:-false}" -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +export DATA_DIR_INITIALIZED="${DATA_DIR_INITIALIZED:-no}" +export CONFIG_DIR_INITIALIZED="${CONFIG_DIR_INITIALIZED:-no}" +# - - - - - - - - - - - - - - - - - - - - - - - - - # System export LANG="${LANG:-C.UTF-8}" export LC_ALL="${LANG:-C.UTF-8}" export TZ="${TZ:-${TIMEZONE:-America/New_York}}" export HOSTNAME="${FULL_DOMAIN_NAME:-${SERVER_HOSTNAME:-$HOSTNAME}}" -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # Default directories export SSL_DIR="${SSL_DIR:-/config/ssl}" -export SSL_CA="${SSL_CERT:-/config/ssl/ca.crt}" +export SSL_CA="${SSL_CA:-/config/ssl/ca.crt}" export SSL_KEY="${SSL_KEY:-/config/ssl/localhost.pem}" export SSL_CERT="${SSL_CERT:-/config/ssl/localhost.crt}" export LOCAL_BIN_DIR="${LOCAL_BIN_DIR:-/usr/local/bin}" export DEFAULT_DATA_DIR="${DEFAULT_DATA_DIR:-/usr/local/share/template-files/data}" export DEFAULT_CONF_DIR="${DEFAULT_CONF_DIR:-/usr/local/share/template-files/config}" export DEFAULT_TEMPLATE_DIR="${DEFAULT_TEMPLATE_DIR:-/usr/local/share/template-files/defaults}" -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # Backup settings export BACKUP_MAX_DAYS="${BACKUP_MAX_DAYS:-}" export BACKUP_RUN_CRON="${BACKUP_RUN_CRON:-}" export BACKUP_DIR="${BACKUP_DIR:-/data/backups}" -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - CONTAINER_IP4_ADDRESS="${CONTAINER_IP4_ADDRESS:-$(__get_ip4)}" CONTAINER_IP6_ADDRESS="${CONTAINER_IP6_ADDRESS:-$(__get_ip6)}" -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # Additional export WORK_DIR="${ENV_WORK_DIR:-$WORK_DIR}" export SET_RANDOM_PASS="${SET_RANDOM_PASS:-$(__random_password 16)}" @@ -1366,15 +1716,33 @@ export ENTRYPOINT_PID_FILE="${ENTRYPOINT_PID_FILE:-/run/.entrypoint.pid}" export ENTRYPOINT_INIT_FILE="${ENTRYPOINT_INIT_FILE:-/config/.entrypoint.done}" export ENTRYPOINT_DATA_INIT_FILE="${ENTRYPOINT_DATA_INIT_FILE:-/data/.docker_has_run}" export ENTRYPOINT_CONFIG_INIT_FILE="${ENTRYPOINT_CONFIG_INIT_FILE:-/config/.docker_has_run}" -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # is already Initialized -[ -z "$DATA_DIR_INITIALIZED" ] && { [ -f "$ENTRYPOINT_DATA_INIT_FILE" ] && DATA_DIR_INITIALIZED="true" || DATA_DIR_INITIALIZED="false"; } -[ -z "$CONFIG_DIR_INITIALIZED" ] && { [ -f "$ENTRYPOINT_CONFIG_INIT_FILE" ] && CONFIG_DIR_INITIALIZED="true" || CONFIG_DIR_INITIALIZED="false"; } -[ -z "$ENTRYPOINT_FIRST_RUN" ] && { { [ -f "$ENTRYPOINT_PID_FILE" ] || [ -f "$ENTRYPOINT_INIT_FILE" ]; } && ENTRYPOINT_FIRST_RUN="no" || ENTRYPOINT_FIRST_RUN="true"; } +if [ -z "$DATA_DIR_INITIALIZED" ]; then + if [ -f "$ENTRYPOINT_DATA_INIT_FILE" ]; then + DATA_DIR_INITIALIZED="yes" + else + DATA_DIR_INITIALIZED="no" + fi +fi +if [ -z "$CONFIG_DIR_INITIALIZED" ]; then + if [ -f "$ENTRYPOINT_CONFIG_INIT_FILE" ]; then + CONFIG_DIR_INITIALIZED="yes" + else + CONFIG_DIR_INITIALIZED="no" + fi +fi +if [ -z "$ENTRYPOINT_FIRST_RUN" ]; then + if [ -f "$ENTRYPOINT_PID_FILE" ] || [ -f "$ENTRYPOINT_INIT_FILE" ]; then + ENTRYPOINT_FIRST_RUN="no" + else + ENTRYPOINT_FIRST_RUN="yes" + fi +fi export ENTRYPOINT_DATA_INIT_FILE DATA_DIR_INITIALIZED ENTRYPOINT_CONFIG_INIT_FILE CONFIG_DIR_INITIALIZED export ENTRYPOINT_PID_FILE ENTRYPOINT_INIT_FILE ENTRYPOINT_FIRST_RUN -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # export the functions export -f __get_pid __start_init_scripts __is_running __certbot __update_ssl_certs __create_ssl_cert -# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +# - - - - - - - - - - - - - - - - - - - - - - - - - # end of functions