Harden user_manage, update_system, and the Zimbra pair
user_manage.sh ran useradd/userdel/usermod with no privilege check at
all, so an ordinary user got "Failed to create user." with no hint that
root was the missing piece. Mutating subcommands now require root while
listusers/listgroups stay open, and the check runs *after* the
subcommand is recognised so a bare invocation still prints usage instead
of complaining about privileges. Account names are validated before
reaching useradd, and `deluser` -- which removes the home directory
irrecoverably -- prints what it will delete and confirms first.
zimbra_backup.sh reported success on failed backups. getRestURL can
write an HTTP error body and still exit zero, so a "✅ Backup completed"
could sit over a file containing an error page. Size and gzip -t checks
now gate that, and a suspect file is renamed .suspect rather than
deleted, so it can be looked at. zimbra_restore.sh likewise validates
the archive before starting a restore from it.
Both Zimbra scripts had `cmd` followed by `if [ $? -eq 0 ]`. Adding
set -e to those would have made the error branches unreachable -- set -e
exits before the check -- so the tests are inline instead. That would
have been a silent regression rather than a visible one.
update_system.sh gained strict mode, and a note on the pacman branch:
Arch has no supported partial-upgrade path, and --noconfirm answers away
the prompts that would otherwise warn.
Integrity checks verified against an error page, a truncated archive, a
non-gzip file and a real one.
This commit is contained in:
+12
-3
@@ -14,6 +14,8 @@
|
||||
# You should have received a copy of the GNU General Public License along
|
||||
# with this program. If not, see <https://www.gnu.org/licenses/>.
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
# Ensure script is run as root or with sudo
|
||||
if [ "$EUID" -ne 0 ]; then
|
||||
echo "❌ This script must be run as root or with sudo."
|
||||
@@ -70,10 +72,17 @@ echo "🔄 Restoring backup..."
|
||||
# arrive as positional arguments. Interpolating them (as this line
|
||||
# previously did) let shell metacharacters in either value run commands
|
||||
# as the zimbra user.
|
||||
sudo -u zimbra bash -c '/opt/zimbra/bin/zmmailbox -z -m "$1" postRestURL "/?fmt=tgz&resolve=skip" --file "$2"' _ "$EMAIL" "$FULL_PATH"
|
||||
# Refuse a backup that is not a readable gzip stream before handing it to
|
||||
# zmmailbox -- a truncated or error-page "backup" should fail here, with
|
||||
# a clear reason, rather than part way through a restore.
|
||||
if ! gzip -t -- "$FULL_PATH" 2>/dev/null; then
|
||||
echo "❌ $FILENAME is not a valid gzip archive -- refusing to restore from it."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Check result
|
||||
if [ $? -eq 0 ]; then
|
||||
# Tested inline rather than via `$?`: under set -e a failure would exit
|
||||
# before the check, making the error branch below unreachable.
|
||||
if sudo -u zimbra bash -c '/opt/zimbra/bin/zmmailbox -z -m "$1" postRestURL "/?fmt=tgz&resolve=skip" --file "$2"' _ "$EMAIL" "$FULL_PATH"; then
|
||||
echo "✅ Restore completed successfully for $EMAIL"
|
||||
else
|
||||
echo "❌ Restore failed. Please verify mailbox exists and backup file integrity."
|
||||
|
||||
Reference in New Issue
Block a user