Commit Graph
136 Commits
Author SHA1 Message Date
chris 5b811260a5 fix: update early signal trap in recover_bad_signature.sh to pass exit code
Line 1003: changed
       to
2026-09-17 00:58:49 +02:00
chrisandClaude Sonnet 4.6 dfacd0ce83 fix/feat: validation improvements and EXIT trap for all bad-signature scripts
fix: treat qpdf exit code 3 (warnings only) as VALID in PDF check
  - exit 0 and exit 3 both map to VALID; only exit 2 is a structural error
  - error detail now includes first matching error line from qpdf output

fix: add EXIT trap so encryption flag and temp files are always cleaned up
  - changed signal trap from  to
  - EXIT fires for any bash exit including syntax errors and unexpected crashes
  - clean_up() now runs  first to prevent re-entry / infinite loop
  - applies to recover_bad_signature.sh (where the flag matters most),
    restore_bad_signature.sh and recreate_bad_signature.sh

feat: check optional validation tools at startup and offer apt install
  - new check_optional_validation_tools() prompts [j/N] in interactive mode
  - covers: imagemagick (identify), ffmpeg (ffprobe), mp3val, flac, vorbis-tools (ogginfo)

feat: use optional tools for deeper file validation when available
  - PNG / GIF / BMP / TIFF: identify -regard-warnings (full decode) with magic-byte fallback
  - MP4 / MOV / M4V: ffprobe -show_streams (container parse) with ftyp-box fallback
  - MP3: new dedicated case — mp3val frame check with ID3/sync-word fallback
  - FLAC: new dedicated case — flac --silent --test with fLaC-signature fallback
  - OGG / OGA / OGV / OPUS: new dedicated case — ogginfo with OggS-signature fallback

Affects: recover_bad_signature.sh, restore_bad_signature.sh, recreate_bad_signature.sh

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GfXh5sRbEaXiEX6KjAPivc
2026-09-16 19:06:03 +02:00
chris 8234c2d9f3 fix: add EXIT trap to ensure encryption flag and temp files are cleaned up on crash 2026-09-16 14:10:47 +02:00
chrisandClaude Sonnet 4.6 8bfc4d04b7 feat(ux): show temp log file paths after YES confirmation in all scripts
After the user confirms with YES, each script now prints the paths of
the two temporary files that are written continuously during the run,
so they can be monitored with tail -f without having to know the paths
by heart. Affects scan_, recover_, restore_, recreate_bad_signature.sh.
recreate shows per-account log file names since it writes one per user.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GfXh5sRbEaXiEX6KjAPivc
2026-09-16 09:20:55 +02:00
chris eef48a9c8d fix(validate): fix unzip hanging on password-protected ZIPs via setsid
unzip -tq on a password-protected archive tries to open /dev/tty to
prompt for the password. Inside a tmux session this generates SIGTTIN,
which stops the process (ps state T). A stopped process cannot receive
SIGTERM, so timeout waited indefinitely for a child that would never exit.

Fix: wrap all unzip calls with setsid so the process runs in a new
session without a controlling terminal. The /dev/tty open then fails
immediately with ENXIO and unzip exits with a non-zero code instead of
blocking. Additional hardening:
- timeout -k 5: send SIGKILL 5 s after SIGTERM as a last resort
- < /dev/null: also cut off stdin as a secondary safeguard
- exit 137 (128+9, SIGKILL) treated as timeout alongside 124
- error output matching "password"/"encrypt"/"need PK compat" reported
  as UNVERIFIED instead of INVALID

Affects: recover_bad_signature.sh, restore_bad_signature.sh,
         recreate_bad_signature.sh
2026-09-16 08:55:50 +02:00
chris 6677f4f0c2 fix(validate): add 120s timeout to unzip integrity checks
unzip -tq can block indefinitely on very large or partially corrupt
ZIP archives (stalls in I/O rather than exiting with a CRC error).
All three scripts that call validate_recovered_file() are affected:
recover_, restore_, recreate_bad_signature.sh.

Both the quick check (unzip -tq) and the verbose error pass (unzip -t)
are now wrapped with `timeout 120`. Exit code 124 (timed out) is
reported as UNVERIFIED with a hint for manual follow-up; any other
non-zero exit is still reported as INVALID with the first error line.
2026-09-16 00:44:02 +02:00
chris b33b859cf2 Fix: Vorzeitiger Abbruch bei großen Accounts nach 3600s Laufzeit
Betroffen: scan_, recover_, restore_, recreate_bad_signature.sh
           und diagnose_share_key.sh

Bei Accounts mit sehr vielen bzw. sehr großen Dateien konnte der
jeweilige Pro-Account-Durchlauf länger als eine Stunde dauern und
wurde dann von PHP mit "Maximum execution time of 3600 seconds
exceeded" abgebrochen - mitten im Lauf, ohne jedes Ergebnis.

- su -c "$PHP_BIN ..." ruft PHP jetzt zusätzlich mit
  -d max_execution_time=0 auf.
- Das allein reicht nicht: Nextclouds eigenes lib/base.php setzt
  beim Bootstrap unbedingt (fest einprogrammiert, nicht
  konfigurierbar) set_time_limit(3600) und überschreibt damit den
  CLI-Flag wieder. Daher zusätzlich direkt nach dem require von
  lib/base.php ein erneutes set_time_limit(0) in jedem der fünf
  eingebetteten PHP-Scripte, das Nextclouds Reset seinerseits
  rückgängig macht.

Kein Verhaltensunterschied für kleine/normale Accounts, betrifft
nur die maximale Laufzeit pro Account.
2026-09-15 21:01:03 +02:00
chris 44f143fbe8 diagnose_share_key.sh: some changes on script output. 2026-09-15 01:17:59 +02:00
chris b1e02b737c Add sone documentation and README's. 2026-09-15 00:27:01 +02:00
chris a8887aeeea delete_files.sh: neues, generisches Script zum gezielten Löschen von Dateien 2026-09-15 00:26:19 +02:00
chris 93e0576777 Some minor changes on scriptb output. 2026-09-15 00:24:31 +02:00
chris 54f16e0a20 occ_scan_bad_signature.sh was replaced by scan_bad_signature.sh 2026-09-14 23:58:32 +02:00
chris f108a71a80 Add Nextcloud bad-signature recovery toolkit 2026-09-14 15:08:53 +02:00
chris c8997cc2e1 Add script 'recover_bad_signature.sh'. 2026-09-11 22:20:59 +02:00
chris 6605d6ab69 scan_bad_signature.sh: add a month-by-month count of bad-signature files, per account and
overall, in both console output and the report file. Helps tell apart
a one-off historical incident from an ongoing/recurring problem.
2026-09-11 14:04:45 +02:00
chris 62417ef150 scan_bad_signature.sh: add period of the finds to the statistics. 2026-09-11 13:54:42 +02:00
chris 94a73f6450 scan_bad_signature.sh: warn if encryption is NOT enabled. 2026-09-11 13:38:14 +02:00
chris dc8948c4de scan_bad_signature.sh: adjust script output. 2026-09-11 13:21:11 +02:00
chris 4e14ee6dbe Add script 'scan_bad_signature.sh'. 2026-09-11 13:13:21 +02:00
chris 94d80c6dfb occ_maintenance.sh: remove LOCK directory if no previos process is running. 2026-04-13 00:07:30 +02:00
chris 6995075721 occ_maintenance.sh: fix error in removing LOCK directory. 2026-04-13 00:03:03 +02:00
chris 81a66209d6 occ_maintenance.sh: Suppress pgrep output in if clause using grep -q . 2026-04-12 22:42:11 +02:00
chris 0ae2bad29b occ_maintenance.sh: don't start if script is already running. 2026-04-12 16:22:02 +02:00
chris 416960f84c update_nextcloud.sh: empty log file at end of the script. 2025-12-20 23:38:21 +01:00
chris 28a7c7aa78 Add script 'get-app-list.sh'. 2025-12-15 21:28:35 +01:00
chris 4ae3118aa8 Fix error in determin systemd support for debian 13 and newer. 2025-12-15 18:05:14 +01:00
chris 09b9273a8d fix error in host configuration. 2025-12-06 13:35:40 +01:00
chris b1f7186090 Support script-driven upgrades for version 32.0.x 2025-12-06 13:02:08 +01:00
chris 7efb678dfb update_nextcloud.sh: reinstall notify_push if this app was installed befor. 2025-12-04 17:13:42 +01:00
chris 3a652d14a1 Add script 'reinstall-notify_push.sh'. 2025-12-04 17:12:52 +01:00
chris c97c7e4163 Add script 'unban-ip-from-redis-cache.sh'. 2025-09-26 13:30:41 +02:00
chris 187310ecb9 Add file 'README.integrity-check'. 2025-07-20 10:42:18 +02:00
chris 793b1b1e1c update_nextcloud.sh: use realpath for data dirctory. 2025-06-20 22:05:33 +02:00
chris b6fd1ab6a3 add-new-account.sh: supprt blank sign in account name. 2025-05-02 18:24:48 +02:00
chris d60a7d5937 update_nextcloud.sh: restart notify_push service if present.. 2025-04-22 17:40:21 +02:00
chris 9346c73f39 A realy smal change on script output. 2025-04-20 02:11:27 +02:00
chris 23edc5828c Add script 'add-new-account.sh'. 2025-04-20 02:07:01 +02:00
chris 73f2f79324 snippets/get-cloud-instance-to-update.sh: a really smal change - remove a blank sign.. 2025-03-30 18:24:15 +02:00
chris 78a10d9169 Add script 'remove-old-nc-installations.sh'. 2025-03-30 18:23:24 +02:00
chris 9893bd4371 restore_nextcloud.sh: some changes in error handling. 2025-03-29 03:06:33 +01:00
chris 00cce38bf1 Add script 'correct-cloud-database-row-format.sh'. 2025-03-28 01:55:32 +01:00
chris 4abff5e4fa update_nextcloud.sh: run 'Migrating the mimetypes' job after update. 2024-10-19 01:43:03 +02:00
chris 6882e48d80 Add 'script occ_migrate_mimetipes.sh'. 2024-08-25 00:35:22 +02:00
chris ab1256f14b update_nextcloud.sh: some changes in script output. 2024-03-31 03:01:42 +02:00
chris a9fb3067df update_nextcloud.sh: start the cronjon manually only on demand. 2023-12-23 02:28:46 +01:00
chris b5a0204dec Some minor changes on script output. 2023-12-18 01:50:28 +01:00
chris ebdccd5c44 occ_maintenance.sh: some minor changes to the script output. 2023-08-05 00:42:42 +02:00
chris 588eb68502 fix error determin configuration file. 2023-08-04 01:39:40 +02:00
chris 2f8d771420 Merge branch 'master' of https://git.oopen.de/script/nextcloud 2023-08-04 01:28:53 +02:00
chris bea755c670 occ_maintenance.sh: fix error determin configuration file. 2023-08-04 01:28:23 +02:00