From a22102c2635507e98e75b993583115d049ed3986 Mon Sep 17 00:00:00 2001 From: tjh Date: Sun, 12 Oct 2025 11:07:55 +0100 Subject: [PATCH] use strict variable expansion and don't provide defaults Signed-off-by: tjh --- src/README.md.sh | 1 + src/knotserver-git/README.md.sh | 5 +++-- src/knotserver-shared/install.sh | 5 +++-- src/knotserver-shared/service.sh | 13 +++++++------ src/knotserver-shared/sshd.conf.sh | 5 +++-- src/knotserver-shared/tmpfiles.conf.sh | 5 +++-- src/knotserver/PKGBUILD.sh | 1 + src/knotserver/README.md.sh | 5 +++-- src/spindle/PKGBUILD.sh | 1 + src/spindle/service.sh | 9 +++++---- src/spindle/tmpfiles.conf.sh | 3 ++- update.sh | 1 + 12 files changed, 33 insertions(+), 21 deletions(-) diff --git a/src/README.md.sh b/src/README.md.sh index b8ba56f..09a24cf 100644 --- a/src/README.md.sh +++ b/src/README.md.sh @@ -1,4 +1,5 @@ #!/usr/bin/bash +set -eu cat << EOF > ${pkgbuild_path}/README.md # pkgs diff --git a/src/knotserver-git/README.md.sh b/src/knotserver-git/README.md.sh index a7c6d7c..e0287c2 100644 --- a/src/knotserver-git/README.md.sh +++ b/src/knotserver-git/README.md.sh @@ -1,4 +1,5 @@ #!/usr/bin/bash +set -eu cat << EOF > ${pkgbuild_path}/README.md # knotserver-git @@ -10,11 +11,11 @@ be stored in \`${knotserver_repo_path}\`. ## SSH SSH access is required to push to repositories. To enable, use the sshd_config.d drop-in, and give the -\`${knotserver_user:-git}\` user a shell and a home directory: +\`${knotserver_user}\` user a shell and a home directory: \`\`\`bash ln -s /usr/lib/systemd/sshd_config.d/knotserver.conf /etc/ssh/sshd_config.d/30-knotserver.conf -usermod -s /usr/bin/bash -d ${knotserver_repo_path} ${knotserver_user:-git} +usermod -s /usr/bin/bash -d ${knotserver_repo_path} ${knotserver_user} \`\`\` EOF diff --git a/src/knotserver-shared/install.sh b/src/knotserver-shared/install.sh index 6240b8d..ae08db5 100644 --- a/src/knotserver-shared/install.sh +++ b/src/knotserver-shared/install.sh @@ -1,15 +1,16 @@ #!/usr/bin/bash +set -eu cat << EOF > ${pkgbuild_path}/knotserver.install post_install() { echo - echo knotserver installed, with repositories stored in: ${knotserver_repo_path:-/var/lib/tangled/repositories} + echo knotserver installed, with repositories stored in: ${knotserver_repo_path} echo echo Use "systemctl edit knotserver.service" to set "KNOT_SERVER_OWNER" to the DID of the knot owner, echo and override "KNOT_SERVER_HOSTNAME" if 'hostname' does not return the FQDN echo of your knot. echo echo To enable git push over ssh for tangled repositories, run: echo " ln -s /usr/lib/systemd/sshd_config.d/knotserver.conf /etc/ssh/sshd_config.d/30-knotserver.conf" - echo " usermod -s /usr/bin/bash -d ${knotserver_repo_path:-/var/lib/tangled/repositories} ${knotserver_user:-git}" + echo " usermod -s /usr/bin/bash -d ${knotserver_repo_path} ${knotserver_user}" echo echo and reload sshd echo diff --git a/src/knotserver-shared/service.sh b/src/knotserver-shared/service.sh index a9355da..1f59210 100644 --- a/src/knotserver-shared/service.sh +++ b/src/knotserver-shared/service.sh @@ -1,21 +1,22 @@ #!/usr/bin/bash +set -eu cat << EOF > ${pkgbuild_path}/knotserver.service [Unit] Description=tangled knot server After=network.target network-online.target Wants=network-online.target -AssertPathExists=${knotserver_path:-/var/lib/tangled} -AssertPathExists=${knotserver_repo_path:-/var/lib/tangled/repositories} +AssertPathExists=${knotserver_path} +AssertPathExists=${knotserver_repo_path} [Service] Environment="KNOT_SERVER_HOSTNAME=%H" Environment="KNOT_SERVER_LISTEN_ADDR=127.0.0.1:5555" -Environment="KNOT_REPO_SCAN_PATH=${knotserver_repo_path:-/var/lib/tangled/repositories}" -WorkingDirectory=${knotserver_path:-/var/lib/tangled} +Environment="KNOT_REPO_SCAN_PATH=${knotserver_repo_path}" +WorkingDirectory=${knotserver_path} ExecStart=/usr/bin/knot server Restart=always -User=${knotserver_user:-git} -Group=${knotserver_group:-git} +User=${knotserver_user} +Group=${knotserver_group} StandardOutput=journal StandardError=journal diff --git a/src/knotserver-shared/sshd.conf.sh b/src/knotserver-shared/sshd.conf.sh index a5515b7..d508c11 100644 --- a/src/knotserver-shared/sshd.conf.sh +++ b/src/knotserver-shared/sshd.conf.sh @@ -1,6 +1,7 @@ #!/usr/bin/bash +set -eu cat << EOF > ${pkgbuild_path}/knotserver-sshd.conf -Match User ${knotserver_user:-git} - AuthorizedKeysCommand /usr/bin/knot keys -output authorized-keys -git-dir ${knotserver_repo_path:-/var/lib/tangled/repositories} -log-path ${knotserver_log_directory:-/var/log/knotserver}/keyfetch.log +Match User ${knotserver_user} + AuthorizedKeysCommand /usr/bin/knot keys -output authorized-keys -git-dir ${knotserver_repo_path} -log-path ${knotserver_log_directory}/keyfetch.log AuthorizedKeysCommandUser nobody EOF diff --git a/src/knotserver-shared/tmpfiles.conf.sh b/src/knotserver-shared/tmpfiles.conf.sh index 742fd50..ad70ed7 100644 --- a/src/knotserver-shared/tmpfiles.conf.sh +++ b/src/knotserver-shared/tmpfiles.conf.sh @@ -1,6 +1,7 @@ #!/usr/bin/bash +set -eu cat << EOF > ${pkgbuild_path}/knotserver-tmpfiles.conf d /etc/tangled 700 root root -d ${knotserver_path:-/var/lib/tangled} 755 ${knotserver_user:-git} ${knotserver_group:-git} - -d ${knotserver_repo_path:-/var/lib/tangled/repositories} 755 ${knotserver_user:-git} ${knotserver_group:-git} - +d ${knotserver_path} 755 ${knotserver_user} ${knotserver_group} - +d ${knotserver_repo_path} 755 ${knotserver_user} ${knotserver_group} - EOF diff --git a/src/knotserver/PKGBUILD.sh b/src/knotserver/PKGBUILD.sh index ef56f88..85865cb 100644 --- a/src/knotserver/PKGBUILD.sh +++ b/src/knotserver/PKGBUILD.sh @@ -1,4 +1,5 @@ #!/usr/bin/bash +set -eu cat << EOF > ${pkgbuild_path}/PKGBUILD _pkgname=knotserver _pkgver=${tag} diff --git a/src/knotserver/README.md.sh b/src/knotserver/README.md.sh index 22b7b55..0abfecf 100644 --- a/src/knotserver/README.md.sh +++ b/src/knotserver/README.md.sh @@ -1,4 +1,5 @@ #!/usr/bin/bash +set -eu cat << EOF > ${pkgbuild_path}/README.md # knotserver @@ -10,11 +11,11 @@ be stored in \`${knotserver_repo_path}\`. ## SSH SSH access is required to push to repositories. To enable, use the sshd_config.d drop-in, and give the -\`${knotserver_user:-git}\` user a shell and a home directory: +\`${knotserver_user}\` user a shell and a home directory: \`\`\`bash ln -s /usr/lib/systemd/sshd_config.d/knotserver.conf /etc/ssh/sshd_config.d/30-knotserver.conf -usermod -s /usr/bin/bash -d ${knotserver_repo_path} ${knotserver_user:-git} +usermod -s /usr/bin/bash -d ${knotserver_repo_path} ${knotserver_user} \`\`\` EOF diff --git a/src/spindle/PKGBUILD.sh b/src/spindle/PKGBUILD.sh index 41b1e1f..013523d 100755 --- a/src/spindle/PKGBUILD.sh +++ b/src/spindle/PKGBUILD.sh @@ -1,4 +1,5 @@ #!/usr/bin/bash +set -eu cat << EOF > ${pkgbuild_path}/PKGBUILD _pkgname=spindle _pkgver=${tag} diff --git a/src/spindle/service.sh b/src/spindle/service.sh index 8310cd0..90c3087 100755 --- a/src/spindle/service.sh +++ b/src/spindle/service.sh @@ -1,19 +1,20 @@ #!/usr/bin/bash +set -eu cat << EOF > ${pkgbuild_path}/spindle.service [Unit] Description=tangled spindle server After=network.target network-online.target docker.service Wants=network-online.target -AssertPathExists=${spindle_path:-/var/lib/spindle} +AssertPathExists=${spindle_path} [Service] Environment="SPINDLE_SERVER_HOSTNAME=%H" Environment="SPINDLE_SERVER_LISTEN_ADDR=127.0.0.1:6555" -WorkingDirectory=${spindle_path:-/var/lib/spindle} +WorkingDirectory=${spindle_path} ExecStart=/usr/bin/spindle Restart=always -User=${spindle_user:-root} -Group=${spindle_group:-root} +User=${spindle_user} +Group=${spindle_group} StandardOutput=journal StandardError=journal LimitNOFILE=65536 diff --git a/src/spindle/tmpfiles.conf.sh b/src/spindle/tmpfiles.conf.sh index 83a8f77..1131ef2 100755 --- a/src/spindle/tmpfiles.conf.sh +++ b/src/spindle/tmpfiles.conf.sh @@ -1,4 +1,5 @@ #!/usr/bin/bash +set -eu cat << EOF > ${pkgbuild_path}/spindle-tmpfiles.conf -d ${spindle_path:-/var/lib/tangled} 755 ${spindle_user:-root} ${spindle_group:-root} - +d ${spindle_path} 755 ${spindle_user} ${spindle_group} - EOF diff --git a/update.sh b/update.sh index 6b945d7..d61a3e8 100755 --- a/update.sh +++ b/update.sh @@ -1,4 +1,5 @@ #!/usr/bin/env bash +set -eu source ./conf.sh -- 2.51.2