Commit Graph
132 Commits
Author SHA1 Message Date
chris eef48a9c8d fix(validate): fix unzip hanging on password-protected ZIPs via setsid
unzip -tq on a password-protected archive tries to open /dev/tty to
prompt for the password. Inside a tmux session this generates SIGTTIN,
which stops the process (ps state T). A stopped process cannot receive
SIGTERM, so timeout waited indefinitely for a child that would never exit.

Fix: wrap all unzip calls with setsid so the process runs in a new
session without a controlling terminal. The /dev/tty open then fails
immediately with ENXIO and unzip exits with a non-zero code instead of
blocking. Additional hardening:
- timeout -k 5: send SIGKILL 5 s after SIGTERM as a last resort
- < /dev/null: also cut off stdin as a secondary safeguard
- exit 137 (128+9, SIGKILL) treated as timeout alongside 124
- error output matching "password"/"encrypt"/"need PK compat" reported
  as UNVERIFIED instead of INVALID

Affects: recover_bad_signature.sh, restore_bad_signature.sh,
         recreate_bad_signature.sh
2026-09-16 08:55:50 +02:00
chris 6677f4f0c2 fix(validate): add 120s timeout to unzip integrity checks
unzip -tq can block indefinitely on very large or partially corrupt
ZIP archives (stalls in I/O rather than exiting with a CRC error).
All three scripts that call validate_recovered_file() are affected:
recover_, restore_, recreate_bad_signature.sh.

Both the quick check (unzip -tq) and the verbose error pass (unzip -t)
are now wrapped with `timeout 120`. Exit code 124 (timed out) is
reported as UNVERIFIED with a hint for manual follow-up; any other
non-zero exit is still reported as INVALID with the first error line.
2026-09-16 00:44:02 +02:00
chris b33b859cf2 Fix: Vorzeitiger Abbruch bei großen Accounts nach 3600s Laufzeit
Betroffen: scan_, recover_, restore_, recreate_bad_signature.sh
           und diagnose_share_key.sh

Bei Accounts mit sehr vielen bzw. sehr großen Dateien konnte der
jeweilige Pro-Account-Durchlauf länger als eine Stunde dauern und
wurde dann von PHP mit "Maximum execution time of 3600 seconds
exceeded" abgebrochen - mitten im Lauf, ohne jedes Ergebnis.

- su -c "$PHP_BIN ..." ruft PHP jetzt zusätzlich mit
  -d max_execution_time=0 auf.
- Das allein reicht nicht: Nextclouds eigenes lib/base.php setzt
  beim Bootstrap unbedingt (fest einprogrammiert, nicht
  konfigurierbar) set_time_limit(3600) und überschreibt damit den
  CLI-Flag wieder. Daher zusätzlich direkt nach dem require von
  lib/base.php ein erneutes set_time_limit(0) in jedem der fünf
  eingebetteten PHP-Scripte, das Nextclouds Reset seinerseits
  rückgängig macht.

Kein Verhaltensunterschied für kleine/normale Accounts, betrifft
nur die maximale Laufzeit pro Account.
2026-09-15 21:01:03 +02:00
chris 44f143fbe8 diagnose_share_key.sh: some changes on script output. 2026-09-15 01:17:59 +02:00
chris b1e02b737c Add sone documentation and README's. 2026-09-15 00:27:01 +02:00
chris a8887aeeea delete_files.sh: neues, generisches Script zum gezielten Löschen von Dateien 2026-09-15 00:26:19 +02:00
chris 93e0576777 Some minor changes on scriptb output. 2026-09-15 00:24:31 +02:00
chris 54f16e0a20 occ_scan_bad_signature.sh was replaced by scan_bad_signature.sh 2026-09-14 23:58:32 +02:00
chris f108a71a80 Add Nextcloud bad-signature recovery toolkit 2026-09-14 15:08:53 +02:00
chris c8997cc2e1 Add script 'recover_bad_signature.sh'. 2026-09-11 22:20:59 +02:00
chris 6605d6ab69 scan_bad_signature.sh: add a month-by-month count of bad-signature files, per account and
overall, in both console output and the report file. Helps tell apart
a one-off historical incident from an ongoing/recurring problem.
2026-09-11 14:04:45 +02:00
chris 62417ef150 scan_bad_signature.sh: add period of the finds to the statistics. 2026-09-11 13:54:42 +02:00
chris 94a73f6450 scan_bad_signature.sh: warn if encryption is NOT enabled. 2026-09-11 13:38:14 +02:00
chris dc8948c4de scan_bad_signature.sh: adjust script output. 2026-09-11 13:21:11 +02:00
chris 4e14ee6dbe Add script 'scan_bad_signature.sh'. 2026-09-11 13:13:21 +02:00
chris 94d80c6dfb occ_maintenance.sh: remove LOCK directory if no previos process is running. 2026-04-13 00:07:30 +02:00
chris 6995075721 occ_maintenance.sh: fix error in removing LOCK directory. 2026-04-13 00:03:03 +02:00
chris 81a66209d6 occ_maintenance.sh: Suppress pgrep output in if clause using grep -q . 2026-04-12 22:42:11 +02:00
chris 0ae2bad29b occ_maintenance.sh: don't start if script is already running. 2026-04-12 16:22:02 +02:00
chris 416960f84c update_nextcloud.sh: empty log file at end of the script. 2025-12-20 23:38:21 +01:00
chris 28a7c7aa78 Add script 'get-app-list.sh'. 2025-12-15 21:28:35 +01:00
chris 4ae3118aa8 Fix error in determin systemd support for debian 13 and newer. 2025-12-15 18:05:14 +01:00
chris 09b9273a8d fix error in host configuration. 2025-12-06 13:35:40 +01:00
chris b1f7186090 Support script-driven upgrades for version 32.0.x 2025-12-06 13:02:08 +01:00
chris 7efb678dfb update_nextcloud.sh: reinstall notify_push if this app was installed befor. 2025-12-04 17:13:42 +01:00
chris 3a652d14a1 Add script 'reinstall-notify_push.sh'. 2025-12-04 17:12:52 +01:00
chris c97c7e4163 Add script 'unban-ip-from-redis-cache.sh'. 2025-09-26 13:30:41 +02:00
chris 187310ecb9 Add file 'README.integrity-check'. 2025-07-20 10:42:18 +02:00
chris 793b1b1e1c update_nextcloud.sh: use realpath for data dirctory. 2025-06-20 22:05:33 +02:00
chris b6fd1ab6a3 add-new-account.sh: supprt blank sign in account name. 2025-05-02 18:24:48 +02:00
chris d60a7d5937 update_nextcloud.sh: restart notify_push service if present.. 2025-04-22 17:40:21 +02:00
chris 9346c73f39 A realy smal change on script output. 2025-04-20 02:11:27 +02:00
chris 23edc5828c Add script 'add-new-account.sh'. 2025-04-20 02:07:01 +02:00
chris 73f2f79324 snippets/get-cloud-instance-to-update.sh: a really smal change - remove a blank sign.. 2025-03-30 18:24:15 +02:00
chris 78a10d9169 Add script 'remove-old-nc-installations.sh'. 2025-03-30 18:23:24 +02:00
chris 9893bd4371 restore_nextcloud.sh: some changes in error handling. 2025-03-29 03:06:33 +01:00
chris 00cce38bf1 Add script 'correct-cloud-database-row-format.sh'. 2025-03-28 01:55:32 +01:00
chris 4abff5e4fa update_nextcloud.sh: run 'Migrating the mimetypes' job after update. 2024-10-19 01:43:03 +02:00
chris 6882e48d80 Add 'script occ_migrate_mimetipes.sh'. 2024-08-25 00:35:22 +02:00
chris ab1256f14b update_nextcloud.sh: some changes in script output. 2024-03-31 03:01:42 +02:00
chris a9fb3067df update_nextcloud.sh: start the cronjon manually only on demand. 2023-12-23 02:28:46 +01:00
chris b5a0204dec Some minor changes on script output. 2023-12-18 01:50:28 +01:00
chris ebdccd5c44 occ_maintenance.sh: some minor changes to the script output. 2023-08-05 00:42:42 +02:00
chris 588eb68502 fix error determin configuration file. 2023-08-04 01:39:40 +02:00
chris 2f8d771420 Merge branch 'master' of https://git.oopen.de/script/nextcloud 2023-08-04 01:28:53 +02:00
chris bea755c670 occ_maintenance.sh: fix error determin configuration file. 2023-08-04 01:28:23 +02:00
chris 2c37b04ddf Some post installations on update and restore scripts. 2023-08-03 10:43:06 +02:00
chris d84294cf0b Add snippet 'get-path-of-php-command.sh' and change concerning code.. 2023-08-03 00:11:02 +02:00
chris 1df7bb124b forgot script 'add_user_to_group.sh'.. 2023-08-02 23:19:58 +02:00
chris 14f062908f Rename snippet 'get-php-major-version' to 'get-php-major-version.sh'.. 2023-08-02 23:17:45 +02:00