Compare commits
15 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| ca06930a50 | |||
| a6f69a13f3 | |||
| 3eacdc8872 | |||
| 87cb43cc85 | |||
| 0a903feb12 | |||
| 15874b002e | |||
| ca9de23ca5 | |||
| d807c40ba5 | |||
| 4125bcccdc | |||
| ac37014628 | |||
| d765ce768f | |||
| 7df117876f | |||
| 12342682b4 | |||
| a734733a87 | |||
| 1a3a23a867 |
@@ -17,11 +17,6 @@ utilsfile="${PI_HOLE_SCRIPT_DIR}/utils.sh"
|
|||||||
# shellcheck source="./advanced/Scripts/utils.sh"
|
# shellcheck source="./advanced/Scripts/utils.sh"
|
||||||
source "${utilsfile}"
|
source "${utilsfile}"
|
||||||
|
|
||||||
# In case we're running at the same time as a system logrotate, use a
|
|
||||||
# separate logrotate state file to prevent stepping on each other's
|
|
||||||
# toes.
|
|
||||||
STATEFILE="/var/lib/logrotate/pihole"
|
|
||||||
|
|
||||||
# Determine database location
|
# Determine database location
|
||||||
DBFILE=$(getFTLConfigValue "files.database")
|
DBFILE=$(getFTLConfigValue "files.database")
|
||||||
if [ -z "$DBFILE" ]; then
|
if [ -z "$DBFILE" ]; then
|
||||||
@@ -42,25 +37,6 @@ if [ -z "$WEBFILE" ]; then
|
|||||||
WEBFILE="/var/log/pihole/webserver.log"
|
WEBFILE="/var/log/pihole/webserver.log"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Helper function to handle log rotation for a single file
|
|
||||||
rotate_log() {
|
|
||||||
# This function copies x.log over to x.log.1
|
|
||||||
# and then empties x.log
|
|
||||||
# Note that moving the file is not an option, as
|
|
||||||
# dnsmasq would happily continue writing into the
|
|
||||||
# moved file (it will have the same file handler)
|
|
||||||
local logfile="$1"
|
|
||||||
if [[ "$*" != *"quiet"* ]]; then
|
|
||||||
echo -ne " ${INFO} Rotating ${logfile} ..."
|
|
||||||
fi
|
|
||||||
cp -p "${logfile}" "${logfile}.1"
|
|
||||||
echo " " > "${logfile}"
|
|
||||||
chmod 640 "${logfile}"
|
|
||||||
if [[ "$*" != *"quiet"* ]]; then
|
|
||||||
echo -e "${OVER} ${TICK} Rotated ${logfile} ..."
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
# Helper function to handle log flushing for a single file
|
# Helper function to handle log flushing for a single file
|
||||||
flush_log() {
|
flush_log() {
|
||||||
local logfile="$1"
|
local logfile="$1"
|
||||||
@@ -78,41 +54,23 @@ flush_log() {
|
|||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
if [[ "$*" == *"once"* ]]; then
|
# Manual flushing
|
||||||
# Nightly logrotation
|
flush_log "${LOGFILE}"
|
||||||
if command -v /usr/sbin/logrotate >/dev/null; then
|
flush_log "${FTLFILE}"
|
||||||
# Logrotate once
|
flush_log "${WEBFILE}"
|
||||||
|
|
||||||
if [[ "$*" != *"quiet"* ]]; then
|
if [[ "$*" != *"quiet"* ]]; then
|
||||||
echo -ne " ${INFO} Running logrotate ..."
|
echo -ne " ${INFO} Flushing database, DNS resolution temporarily unavailable ..."
|
||||||
fi
|
fi
|
||||||
mkdir -p "${STATEFILE%/*}"
|
|
||||||
/usr/sbin/logrotate --force --state "${STATEFILE}" /etc/pihole/logrotate
|
# Stop FTL to make sure it doesn't write to the database while we're deleting data
|
||||||
else
|
service pihole-FTL stop
|
||||||
# Handle rotation for each log file
|
|
||||||
rotate_log "${LOGFILE}"
|
# Delete most recent 24 hours from FTL's database, leave even older data intact (don't wipe out all history)
|
||||||
rotate_log "${FTLFILE}"
|
deleted=$(pihole-FTL sqlite3 -ni "${DBFILE}" "DELETE FROM query_storage WHERE timestamp >= strftime('%s','now')-86400; select changes() from query_storage limit 1")
|
||||||
rotate_log "${WEBFILE}"
|
|
||||||
fi
|
# Restart FTL
|
||||||
else
|
service pihole-FTL restart
|
||||||
# Manual flushing
|
if [[ "$*" != *"quiet"* ]]; then
|
||||||
flush_log "${LOGFILE}"
|
echo -e "${OVER} ${TICK} Deleted ${deleted} queries from long-term query database"
|
||||||
flush_log "${FTLFILE}"
|
|
||||||
flush_log "${WEBFILE}"
|
|
||||||
|
|
||||||
if [[ "$*" != *"quiet"* ]]; then
|
|
||||||
echo -ne " ${INFO} Flushing database, DNS resolution temporarily unavailable ..."
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Stop FTL to make sure it doesn't write to the database while we're deleting data
|
|
||||||
service pihole-FTL stop
|
|
||||||
|
|
||||||
# Delete most recent 24 hours from FTL's database, leave even older data intact (don't wipe out all history)
|
|
||||||
deleted=$(pihole-FTL sqlite3 -ni "${DBFILE}" "DELETE FROM query_storage WHERE timestamp >= strftime('%s','now')-86400; select changes() from query_storage limit 1")
|
|
||||||
|
|
||||||
# Restart FTL
|
|
||||||
service pihole-FTL restart
|
|
||||||
if [[ "$*" != *"quiet"* ]]; then
|
|
||||||
echo -e "${OVER} ${TICK} Deleted ${deleted} queries from long-term query database"
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
|
|||||||
Executable
+72
@@ -0,0 +1,72 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# Pi-hole: A black hole for Internet advertisements
|
||||||
|
# (c) 2025 Pi-hole, LLC (https://pi-hole.net)
|
||||||
|
# Network-wide ad blocking via your own hardware.
|
||||||
|
#
|
||||||
|
# Rotate Pi-hole's log file
|
||||||
|
#
|
||||||
|
# This file is copyright under the latest version of the EUPL.
|
||||||
|
# Please see LICENSE file for your rights under this license.
|
||||||
|
|
||||||
|
colfile="/opt/pihole/COL_TABLE"
|
||||||
|
# shellcheck source="./advanced/Scripts/COL_TABLE"
|
||||||
|
source ${colfile}
|
||||||
|
|
||||||
|
readonly PI_HOLE_SCRIPT_DIR="/opt/pihole"
|
||||||
|
utilsfile="${PI_HOLE_SCRIPT_DIR}/utils.sh"
|
||||||
|
# shellcheck source="./advanced/Scripts/utils.sh"
|
||||||
|
source "${utilsfile}"
|
||||||
|
|
||||||
|
# In case we're running at the same time as a system logrotate, use a
|
||||||
|
# separate logrotate state file to prevent stepping on each other's
|
||||||
|
# toes.
|
||||||
|
STATEFILE="/var/lib/logrotate/pihole"
|
||||||
|
|
||||||
|
|
||||||
|
# Determine log file location
|
||||||
|
LOGFILE=$(getFTLConfigValue "files.log.dnsmasq")
|
||||||
|
if [ -z "$LOGFILE" ]; then
|
||||||
|
LOGFILE="/var/log/pihole/pihole.log"
|
||||||
|
fi
|
||||||
|
FTLFILE=$(getFTLConfigValue "files.log.ftl")
|
||||||
|
if [ -z "$FTLFILE" ]; then
|
||||||
|
FTLFILE="/var/log/pihole/FTL.log"
|
||||||
|
fi
|
||||||
|
WEBFILE=$(getFTLConfigValue "files.log.webserver")
|
||||||
|
if [ -z "$WEBFILE" ]; then
|
||||||
|
WEBFILE="/var/log/pihole/webserver.log"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Helper function to handle log rotation for a single file
|
||||||
|
rotate_log() {
|
||||||
|
# This function copies x.log over to x.log.1
|
||||||
|
# and then empties x.log
|
||||||
|
# Note that moving the file is not an option, as
|
||||||
|
# dnsmasq would happily continue writing into the
|
||||||
|
# moved file (it will have the same file handler)
|
||||||
|
local logfile="$1"
|
||||||
|
if [[ "$*" != *"quiet"* ]]; then
|
||||||
|
echo -ne " ${INFO} Rotating ${logfile} ..."
|
||||||
|
fi
|
||||||
|
cp -p "${logfile}" "${logfile}.1"
|
||||||
|
echo " " > "${logfile}"
|
||||||
|
chmod 640 "${logfile}"
|
||||||
|
if [[ "$*" != *"quiet"* ]]; then
|
||||||
|
echo -e "${OVER} ${TICK} Rotated ${logfile} ..."
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# Nightly logrotation
|
||||||
|
if command -v /usr/sbin/logrotate >/dev/null; then
|
||||||
|
# Logrotate once
|
||||||
|
if [[ "$*" != *"quiet"* ]]; then
|
||||||
|
echo -ne " ${INFO} Running logrotate ..."
|
||||||
|
fi
|
||||||
|
mkdir -p "${STATEFILE%/*}"
|
||||||
|
/usr/sbin/logrotate --force --state "${STATEFILE}" /etc/pihole/logrotate
|
||||||
|
else
|
||||||
|
# Handle rotation for each log file
|
||||||
|
rotate_log "${LOGFILE}"
|
||||||
|
rotate_log "${FTLFILE}"
|
||||||
|
rotate_log "${WEBFILE}"
|
||||||
|
fi
|
||||||
@@ -50,9 +50,10 @@ rm -f "/etc/pihole/GitHubVersions"
|
|||||||
rm -f "/etc/pihole/localbranches"
|
rm -f "/etc/pihole/localbranches"
|
||||||
rm -f "/etc/pihole/localversions"
|
rm -f "/etc/pihole/localversions"
|
||||||
|
|
||||||
# Create new versions file if it does not exist
|
|
||||||
VERSION_FILE="/etc/pihole/versions"
|
VERSION_FILE="/etc/pihole/versions"
|
||||||
touch "${VERSION_FILE}"
|
|
||||||
|
# Truncates the file to zero length if it exists to clear it up, otherwise creates an empty file.
|
||||||
|
truncate -s 0 "${VERSION_FILE}"
|
||||||
chmod 644 "${VERSION_FILE}"
|
chmod 644 "${VERSION_FILE}"
|
||||||
|
|
||||||
# if /pihole.docker.tag file exists, we will use it's value later in this script
|
# if /pihole.docker.tag file exists, we will use it's value later in this script
|
||||||
|
|||||||
@@ -30,9 +30,6 @@ addOrEditKeyValPair() {
|
|||||||
local key="${2}"
|
local key="${2}"
|
||||||
local value="${3}"
|
local value="${3}"
|
||||||
|
|
||||||
# touch file to prevent grep error if file does not exist yet
|
|
||||||
touch "${file}"
|
|
||||||
|
|
||||||
if grep -q "^${key}=" "${file}"; then
|
if grep -q "^${key}=" "${file}"; then
|
||||||
# Key already exists in file, modify the value
|
# Key already exists in file, modify the value
|
||||||
sed -i "/^${key}=/c\\${key}=${value}" "${file}"
|
sed -i "/^${key}=/c\\${key}=${value}" "${file}"
|
||||||
|
|||||||
@@ -57,9 +57,9 @@ start() {
|
|||||||
stop() {
|
stop() {
|
||||||
if is_running; then
|
if is_running; then
|
||||||
kill "${FTL_PID}"
|
kill "${FTL_PID}"
|
||||||
# Give FTL 60 seconds to gracefully stop
|
# Give FTL 120 seconds to gracefully stop
|
||||||
i=1
|
i=1
|
||||||
while [ "${i}" -le 60 ]; do
|
while [ "${i}" -le 120 ]; do
|
||||||
if ! is_running; then
|
if ! is_running; then
|
||||||
break
|
break
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -28,7 +28,7 @@ ExecReload=/bin/kill -HUP $MAINPID
|
|||||||
ExecStopPost=+/opt/pihole/pihole-FTL-poststop.sh
|
ExecStopPost=+/opt/pihole/pihole-FTL-poststop.sh
|
||||||
|
|
||||||
# Use graceful shutdown with a reasonable timeout
|
# Use graceful shutdown with a reasonable timeout
|
||||||
TimeoutStopSec=60s
|
TimeoutStopSec=120s
|
||||||
|
|
||||||
# Make /usr, /boot, /etc and possibly some more folders read-only...
|
# Make /usr, /boot, /etc and possibly some more folders read-only...
|
||||||
ProtectSystem=full
|
ProtectSystem=full
|
||||||
|
|||||||
@@ -24,7 +24,7 @@
|
|||||||
# The flush script will use logrotate if available
|
# The flush script will use logrotate if available
|
||||||
# parameter "once": logrotate only once (default is twice)
|
# parameter "once": logrotate only once (default is twice)
|
||||||
# parameter "quiet": don't print messages
|
# parameter "quiet": don't print messages
|
||||||
00 00 * * * root PATH="$PATH:/usr/sbin:/usr/local/bin/" pihole flush once quiet
|
00 00 * * * root PATH="$PATH:/usr/sbin:/usr/local/bin/" pihole logrotate quiet
|
||||||
|
|
||||||
@reboot root /usr/sbin/logrotate --state /var/lib/logrotate/pihole /etc/pihole/logrotate
|
@reboot root /usr/sbin/logrotate --state /var/lib/logrotate/pihole /etc/pihole/logrotate
|
||||||
|
|
||||||
|
|||||||
@@ -84,7 +84,7 @@ webInterfaceDir="${webroot}/admin"
|
|||||||
piholeGitUrl="https://github.com/pi-hole/pi-hole.git"
|
piholeGitUrl="https://github.com/pi-hole/pi-hole.git"
|
||||||
PI_HOLE_LOCAL_REPO="/etc/.pihole"
|
PI_HOLE_LOCAL_REPO="/etc/.pihole"
|
||||||
# List of pihole scripts, stored in an array
|
# List of pihole scripts, stored in an array
|
||||||
PI_HOLE_FILES=(list piholeDebug piholeLogFlush setupLCD update version gravity uninstall webpage)
|
PI_HOLE_FILES=(list piholeDebug piholeLogFlush piholeLogRotate setupLCD update version gravity uninstall webpage)
|
||||||
# This directory is where the Pi-hole scripts will be installed
|
# This directory is where the Pi-hole scripts will be installed
|
||||||
PI_HOLE_INSTALL_DIR="/opt/pihole"
|
PI_HOLE_INSTALL_DIR="/opt/pihole"
|
||||||
PI_HOLE_CONFIG_DIR="/etc/pihole"
|
PI_HOLE_CONFIG_DIR="/etc/pihole"
|
||||||
@@ -165,6 +165,8 @@ PIHOLE_META_DEPS_APK=(
|
|||||||
cronie
|
cronie
|
||||||
curl
|
curl
|
||||||
dialog
|
dialog
|
||||||
|
doas # sudo replacement
|
||||||
|
doas-sudo-shim
|
||||||
git
|
git
|
||||||
grep
|
grep
|
||||||
iproute2-minimal # piholeARPTable.sh
|
iproute2-minimal # piholeARPTable.sh
|
||||||
@@ -178,7 +180,6 @@ PIHOLE_META_DEPS_APK=(
|
|||||||
procps-ng
|
procps-ng
|
||||||
psmisc
|
psmisc
|
||||||
shadow
|
shadow
|
||||||
sudo
|
|
||||||
tzdata
|
tzdata
|
||||||
unzip
|
unzip
|
||||||
)
|
)
|
||||||
|
|||||||
+13
-2
@@ -100,9 +100,12 @@ Available commands and options:
|
|||||||
-c Include a Pi-hole database integrity check
|
-c Include a Pi-hole database integrity check
|
||||||
.br
|
.br
|
||||||
|
|
||||||
\fB-f, flush\fR
|
\fB-f, flush\fR [quite]
|
||||||
.br
|
.br
|
||||||
Flush the Pi-hole log
|
Flush the Pi-hole log and last 24h from the query database
|
||||||
|
.br
|
||||||
|
|
||||||
|
quite Suppress output
|
||||||
.br
|
.br
|
||||||
|
|
||||||
\fB-r, repair\fR
|
\fB-r, repair\fR
|
||||||
@@ -242,6 +245,14 @@ Available commands and options:
|
|||||||
verbose Show authentication and status messages
|
verbose Show authentication and status messages
|
||||||
.br
|
.br
|
||||||
|
|
||||||
|
\fBlogrotate\fR [quite]
|
||||||
|
.br
|
||||||
|
Rotate Pi-hole's log files
|
||||||
|
.br
|
||||||
|
|
||||||
|
quite Suppress output
|
||||||
|
.br
|
||||||
|
|
||||||
.SH "EXAMPLE"
|
.SH "EXAMPLE"
|
||||||
|
|
||||||
Some usage examples
|
Some usage examples
|
||||||
|
|||||||
@@ -92,8 +92,13 @@ debugFunc() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
flushFunc() {
|
flushFunc() {
|
||||||
"${PI_HOLE_SCRIPT_DIR}"/piholeLogFlush.sh "$@"
|
# unsupported in docker because it requires restarting FTL
|
||||||
exit 0
|
if [ -n "${DOCKER_VERSION}" ]; then
|
||||||
|
unsupportedFunc
|
||||||
|
else
|
||||||
|
"${PI_HOLE_SCRIPT_DIR}"/piholeLogFlush.sh "$@"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
# Deprecated function, should be removed in the future
|
# Deprecated function, should be removed in the future
|
||||||
@@ -105,6 +110,11 @@ arpFunc() {
|
|||||||
exit 0
|
exit 0
|
||||||
}
|
}
|
||||||
|
|
||||||
|
logrotateFunc() {
|
||||||
|
"${PI_HOLE_SCRIPT_DIR}"/piholeLogRotate.sh "$@"
|
||||||
|
exit 0
|
||||||
|
}
|
||||||
|
|
||||||
networkFlush() {
|
networkFlush() {
|
||||||
shift
|
shift
|
||||||
"${PI_HOLE_SCRIPT_DIR}"/piholeNetworkFlush.sh "$@"
|
"${PI_HOLE_SCRIPT_DIR}"/piholeNetworkFlush.sh "$@"
|
||||||
@@ -517,7 +527,8 @@ Debugging Options:
|
|||||||
-d, debug Start a debugging session
|
-d, debug Start a debugging session
|
||||||
Add '-c' or '--check-database' to include a Pi-hole database integrity check
|
Add '-c' or '--check-database' to include a Pi-hole database integrity check
|
||||||
Add '-a' to automatically upload the log to tricorder.pi-hole.net
|
Add '-a' to automatically upload the log to tricorder.pi-hole.net
|
||||||
-f, flush Flush the Pi-hole log
|
-f, flush Flush the Pi-hole logs and last 24h from the query database
|
||||||
|
Add 'quiet' to suppress output messages
|
||||||
-r, repair Repair Pi-hole subsystems
|
-r, repair Repair Pi-hole subsystems
|
||||||
-t, tail [arg] View the live output of the Pi-hole log.
|
-t, tail [arg] View the live output of the Pi-hole log.
|
||||||
Add an optional argument to filter the log
|
Add an optional argument to filter the log
|
||||||
@@ -550,7 +561,9 @@ Options:
|
|||||||
checkout Switch Pi-hole subsystems to a different GitHub branch
|
checkout Switch Pi-hole subsystems to a different GitHub branch
|
||||||
Add '-h' for more info on checkout usage
|
Add '-h' for more info on checkout usage
|
||||||
networkflush Flush information stored in Pi-hole's network tables
|
networkflush Flush information stored in Pi-hole's network tables
|
||||||
Add '--arp' to additionally flush the ARP table ";
|
Add '--arp' to additionally flush the ARP table
|
||||||
|
logrotate Rotate Pi-hole's log files
|
||||||
|
Add 'quiet' to suppress output messages";
|
||||||
exit 0
|
exit 0
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -593,6 +606,7 @@ case "${1}" in
|
|||||||
"arpflush" ) need_root=true;; # Deprecated, use networkflush instead
|
"arpflush" ) need_root=true;; # Deprecated, use networkflush instead
|
||||||
"networkflush" ) need_root=true;;
|
"networkflush" ) need_root=true;;
|
||||||
"-t" | "tail" ) need_root=true;;
|
"-t" | "tail" ) need_root=true;;
|
||||||
|
"logrotate" ) need_root=true;;
|
||||||
* ) helpFunc;;
|
* ) helpFunc;;
|
||||||
esac
|
esac
|
||||||
|
|
||||||
@@ -628,5 +642,6 @@ case "${1}" in
|
|||||||
"arpflush" ) arpFunc "$@";; # Deprecated, use networkflush instead
|
"arpflush" ) arpFunc "$@";; # Deprecated, use networkflush instead
|
||||||
"networkflush" ) networkFlush "$@";;
|
"networkflush" ) networkFlush "$@";;
|
||||||
"-t" | "tail" ) tailFunc "$2";;
|
"-t" | "tail" ) tailFunc "$2";;
|
||||||
|
"logrotate" ) logrotateFunc "$@";;
|
||||||
* ) helpFunc;;
|
* ) helpFunc;;
|
||||||
esac
|
esac
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ def test_key_val_replacement_works(host):
|
|||||||
"""Confirms addOrEditKeyValPair either adds or replaces a key value pair in a given file"""
|
"""Confirms addOrEditKeyValPair either adds or replaces a key value pair in a given file"""
|
||||||
host.run("""
|
host.run("""
|
||||||
source /opt/pihole/utils.sh
|
source /opt/pihole/utils.sh
|
||||||
|
touch ./testoutput
|
||||||
addOrEditKeyValPair "./testoutput" "KEY_ONE" "value1"
|
addOrEditKeyValPair "./testoutput" "KEY_ONE" "value1"
|
||||||
addOrEditKeyValPair "./testoutput" "KEY_TWO" "value2"
|
addOrEditKeyValPair "./testoutput" "KEY_TWO" "value2"
|
||||||
addOrEditKeyValPair "./testoutput" "KEY_ONE" "value3"
|
addOrEditKeyValPair "./testoutput" "KEY_ONE" "value3"
|
||||||
|
|||||||
Reference in New Issue
Block a user