log_inspect.sh discarded grep's stderr and ignored its exit status, so an unprivileged search over root-owned logs was indistinguishable from a search that genuinely found nothing. grep's three outcomes now mean three different things: matched, matched nothing, or could not read everything -- the last of which says so and exits non-zero. Confirmed grep returns 2 rather than 1 in that case, which is why the naive "status -eq 1" check would never have fired. service_manager.sh validates the action before dispatch and requires root for the five that change system state, leaving status and list open to anyone. $action is quoted at both call sites. rsync_magic.sh had --inplace on unconditionally. It writes straight into destination files instead of to a temporary and renaming, so an interrupted run leaves them partially overwritten -- the opposite of what a backup tool should guarantee. Now opt-in, with a warning when used. Its log lives under /var/log and every line pipes through tee, so under pipefail an unprivileged run died on the first line with a bare permission error; it now falls back to stdout rather than failing the sync over its own logging. --delete also confirms before running, since reversing the two arguments erases the backup. disk_cleanup.sh moves from `set -o pipefail` to full strict mode, with the two pipelines that legitimately return non-zero handled at their call sites rather than by leaving the script lax. Its "largest files" walk also gained -xdev, which it was missing while security_audit.sh next door already had it -- without it the walk descends /proc, /sys and every network mount. All fifteen scripts now run under set -euo pipefail.
89 lines
2.8 KiB
Bash
89 lines
2.8 KiB
Bash
#!/bin/bash
|
|
# service_manager.sh - Start/stop/restart and manage system services
|
|
#
|
|
# Copyright (C) 2025 LINUXexpert.org
|
|
#
|
|
# This program is free software: you can redistribute it and/or modify it
|
|
# under the terms of the GNU General Public License as published by the
|
|
# Free Software Foundation, version 3 of the License.
|
|
#
|
|
# This program is distributed in the hope that it will be useful, but
|
|
# WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
|
# or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
|
# for more details.
|
|
#
|
|
# You should have received a copy of the GNU General Public License along
|
|
# with this program. If not, see <https://www.gnu.org/licenses/>.
|
|
#
|
|
# Usage: service_manager.sh <action> <service_name>
|
|
# Actions: start, stop, restart, status, enable, disable, list
|
|
# Description: Uses systemctl or service to control services.
|
|
#
|
|
# status and list are read-only; everything else changes system state
|
|
# and needs root.
|
|
|
|
set -euo pipefail
|
|
|
|
action="${1:-}"
|
|
service="${2:-}"
|
|
|
|
# Validate up front so an unknown action cannot reach systemctl as a
|
|
# bare word, and so the privilege check below has something to gate on.
|
|
case "$action" in
|
|
start|stop|restart|status|enable|disable|list) ;;
|
|
"") echo "Usage: $0 {start|stop|restart|status|enable|disable|list} <service_name>" >&2; exit 1 ;;
|
|
*) echo "Invalid action '$action'. Use start, stop, restart, status, enable, disable, or list." >&2; exit 1 ;;
|
|
esac
|
|
|
|
case "$action" in
|
|
start|stop|restart|enable|disable)
|
|
if [ "$EUID" -ne 0 ]; then
|
|
echo "'$action' changes system state and requires root. Re-run with sudo." >&2
|
|
exit 1
|
|
fi
|
|
;;
|
|
esac
|
|
|
|
if [ "$action" = "list" ]; then
|
|
# List running services
|
|
if command -v systemctl &> /dev/null; then
|
|
systemctl list-units --type=service --state=running
|
|
elif command -v service &> /dev/null; then
|
|
service --status-all 2>&1 | grep '+' # shows running services with [+]
|
|
else
|
|
echo "No service management tool available."
|
|
fi
|
|
exit 0
|
|
fi
|
|
|
|
if [ -z "$action" ] || [ -z "$service" ]; then
|
|
echo "Usage: $0 {start|stop|restart|status|enable|disable|list} <service_name>"
|
|
exit 1
|
|
fi
|
|
|
|
if command -v systemctl &> /dev/null; then
|
|
case "$action" in
|
|
start|stop|restart|status|enable|disable)
|
|
# Quoted: $action is validated above, but leaving it bare invites
|
|
# word-splitting the moment anyone passes it through a variable.
|
|
systemctl "$action" "$service"
|
|
;;
|
|
esac
|
|
elif command -v service &> /dev/null; then
|
|
case "$action" in
|
|
start|stop|restart)
|
|
service "$service" "$action"
|
|
;;
|
|
status)
|
|
service "$service" status
|
|
;;
|
|
*)
|
|
echo "Action '$action' not supported with legacy service command."
|
|
exit 1
|
|
;;
|
|
esac
|
|
else
|
|
echo "No known service manager found (systemctl/service)."
|
|
exit 1
|
|
fi
|