Compare commits
3 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| ec8df55f0d | |||
| 2acb7098d8 | |||
| f2af7c8970 |
@@ -29,12 +29,12 @@ jobs:
|
|||||||
# Initializes the CodeQL tools for scanning.
|
# Initializes the CodeQL tools for scanning.
|
||||||
-
|
-
|
||||||
name: Initialize CodeQL
|
name: Initialize CodeQL
|
||||||
uses: github/codeql-action/init@9e907b5e64f6b83e7804b09294d44122997950d6 #v4.32.3
|
uses: github/codeql-action/init@89a39a4e59826350b863aa6b6252a07ad50cf83e #v4.32.4
|
||||||
with:
|
with:
|
||||||
languages: 'python'
|
languages: 'python'
|
||||||
-
|
-
|
||||||
name: Autobuild
|
name: Autobuild
|
||||||
uses: github/codeql-action/autobuild@9e907b5e64f6b83e7804b09294d44122997950d6 #v4.32.3
|
uses: github/codeql-action/autobuild@89a39a4e59826350b863aa6b6252a07ad50cf83e #v4.32.4
|
||||||
-
|
-
|
||||||
name: Perform CodeQL Analysis
|
name: Perform CodeQL Analysis
|
||||||
uses: github/codeql-action/analyze@9e907b5e64f6b83e7804b09294d44122997950d6 #v4.32.3
|
uses: github/codeql-action/analyze@89a39a4e59826350b863aa6b6252a07ad50cf83e #v4.32.4
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ jobs:
|
|||||||
issues: write
|
issues: write
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/stale@997185467fa4f803885201cee163a9f38240193d #v10.1.1
|
- uses: actions/stale@b5d41d4e1d5dceea10e7104786b73624c18a190f #v10.2.0
|
||||||
with:
|
with:
|
||||||
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
days-before-stale: 30
|
days-before-stale: 30
|
||||||
|
|||||||
@@ -17,7 +17,7 @@ jobs:
|
|||||||
pull-requests: write
|
pull-requests: write
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/stale@997185467fa4f803885201cee163a9f38240193d #v10.1.1
|
- uses: actions/stale@b5d41d4e1d5dceea10e7104786b73624c18a190f #v10.2.0
|
||||||
with:
|
with:
|
||||||
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
repo-token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
# Do not automatically mark PR/issue as stale
|
# Do not automatically mark PR/issue as stale
|
||||||
|
|||||||
@@ -41,22 +41,6 @@ warning1() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
checkout() {
|
checkout() {
|
||||||
|
|
||||||
local skipFTL additionalFlag
|
|
||||||
skipFTL=false
|
|
||||||
# Check arguments
|
|
||||||
for var in "$@"; do
|
|
||||||
case "$var" in
|
|
||||||
"--skipFTL") skipFTL=true ;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
|
|
||||||
if [ "${skipFTL}" == true ]; then
|
|
||||||
additionalFlag="--skipFTL"
|
|
||||||
else
|
|
||||||
additionalFlag=""
|
|
||||||
fi
|
|
||||||
|
|
||||||
local corebranches
|
local corebranches
|
||||||
local webbranches
|
local webbranches
|
||||||
|
|
||||||
@@ -251,7 +235,7 @@ checkout() {
|
|||||||
# Force updating everything
|
# Force updating everything
|
||||||
if [[ ! "${1}" == "web" && ! "${1}" == "ftl" ]]; then
|
if [[ ! "${1}" == "web" && ! "${1}" == "ftl" ]]; then
|
||||||
echo -e " ${INFO} Running installer to upgrade your installation"
|
echo -e " ${INFO} Running installer to upgrade your installation"
|
||||||
if "${PI_HOLE_FILES_DIR}/automated install/basic-install.sh" --unattended ${additionalFlag}; then
|
if "${PI_HOLE_FILES_DIR}/automated install/basic-install.sh" --unattended; then
|
||||||
exit 0
|
exit 0
|
||||||
else
|
else
|
||||||
echo -e " ${COL_RED} Error: Unable to complete update, please contact support${COL_NC}"
|
echo -e " ${COL_RED} Error: Unable to complete update, please contact support${COL_NC}"
|
||||||
|
|||||||
@@ -149,8 +149,6 @@ main() {
|
|||||||
echo -e " ${INFO} Web Interface:\\t${COL_GREEN}up to date${COL_NC}"
|
echo -e " ${INFO} Web Interface:\\t${COL_GREEN}up to date${COL_NC}"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Allow the user to skip this check if they are using a self-compiled FTL binary from an unsupported architecture
|
|
||||||
if [ "${skipFTL}" != true ]; then
|
|
||||||
local funcOutput
|
local funcOutput
|
||||||
funcOutput=$(get_binary_name) #Store output of get_binary_name here
|
funcOutput=$(get_binary_name) #Store output of get_binary_name here
|
||||||
local binary
|
local binary
|
||||||
@@ -178,10 +176,6 @@ main() {
|
|||||||
esac
|
esac
|
||||||
FTL_update=false
|
FTL_update=false
|
||||||
fi
|
fi
|
||||||
else
|
|
||||||
echo -e " ${INFO} FTL:\\t\\t${COL_YELLOW}--skipFTL set - update check skipped${COL_NC}"
|
|
||||||
FTL_update=false
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Determine FTL branch
|
# Determine FTL branch
|
||||||
local ftlBranch
|
local ftlBranch
|
||||||
@@ -228,14 +222,7 @@ main() {
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ "${FTL_update}" == true || "${core_update}" == true ]]; then
|
if [[ "${FTL_update}" == true || "${core_update}" == true ]]; then
|
||||||
local addionalFlag
|
${PI_HOLE_FILES_DIR}/automated\ install/basic-install.sh --repair --unattended || \
|
||||||
|
|
||||||
if [[ ${skipFTL} == true ]]; then
|
|
||||||
addionalFlag="--skipFTL"
|
|
||||||
else
|
|
||||||
addionalFlag=""
|
|
||||||
fi
|
|
||||||
${PI_HOLE_FILES_DIR}/automated\ install/basic-install.sh --repair --unattended ${addionalFlag} || \
|
|
||||||
echo -e "${basicError}" && exit 1
|
echo -e "${basicError}" && exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -255,15 +242,8 @@ main() {
|
|||||||
exit 0
|
exit 0
|
||||||
}
|
}
|
||||||
|
|
||||||
CHECK_ONLY=false
|
if [[ "$1" == "--check-only" ]]; then
|
||||||
skipFTL=false
|
CHECK_ONLY=true
|
||||||
|
fi
|
||||||
# Check arguments
|
|
||||||
for var in "$@"; do
|
|
||||||
case "$var" in
|
|
||||||
"--check-only") CHECK_ONLY=true ;;
|
|
||||||
"--skipFTL") skipFTL=true ;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
|
|
||||||
main
|
main
|
||||||
|
|||||||
@@ -10,32 +10,32 @@
|
|||||||
|
|
||||||
function get_local_branch() {
|
function get_local_branch() {
|
||||||
# Return active branch
|
# Return active branch
|
||||||
cd "${1}" 2>/dev/null || return 1
|
cd "${1}" 2>/dev/null || { echo "null"; return; }
|
||||||
git rev-parse --abbrev-ref HEAD || return 1
|
git rev-parse --abbrev-ref HEAD || echo "null"
|
||||||
}
|
}
|
||||||
|
|
||||||
function get_local_version() {
|
function get_local_version() {
|
||||||
# Return active version
|
# Return active version
|
||||||
cd "${1}" 2>/dev/null || return 1
|
cd "${1}" 2>/dev/null || { echo "null"; return; }
|
||||||
git describe --tags --always 2>/dev/null || return 1
|
git describe --tags --always 2>/dev/null || echo "null"
|
||||||
}
|
}
|
||||||
|
|
||||||
function get_local_hash() {
|
function get_local_hash() {
|
||||||
cd "${1}" 2>/dev/null || return 1
|
cd "${1}" 2>/dev/null || { echo "null"; return; }
|
||||||
git rev-parse --short=8 HEAD || return 1
|
git rev-parse --short=8 HEAD || echo "null"
|
||||||
}
|
}
|
||||||
|
|
||||||
function get_remote_version() {
|
function get_remote_version() {
|
||||||
# if ${2} is = "master" we need to use the "latest" endpoint, otherwise, we simply return null
|
# if ${2} is = "master" we need to use the "latest" endpoint, otherwise, we simply return null
|
||||||
if [[ "${2}" == "master" ]]; then
|
if [[ "${2}" == "master" ]]; then
|
||||||
curl -s "https://api.github.com/repos/pi-hole/${1}/releases/latest" 2>/dev/null | jq --raw-output .tag_name || return 1
|
curl -s "https://api.github.com/repos/pi-hole/${1}/releases/latest" 2>/dev/null | jq --raw-output .tag_name || echo "null"
|
||||||
else
|
else
|
||||||
echo "null"
|
echo "null"
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
function get_remote_hash() {
|
function get_remote_hash() {
|
||||||
git ls-remote "https://github.com/pi-hole/${1}" --tags "${2}" | awk '{print substr($0, 1,8);}' || return 1
|
git ls-remote "https://github.com/pi-hole/${1}" --tags "${2}" | awk '{print substr($0, 1,8);}' || echo "null"
|
||||||
}
|
}
|
||||||
|
|
||||||
# Source the utils file for addOrEditKeyValPair()
|
# Source the utils file for addOrEditKeyValPair()
|
||||||
|
|||||||
+23
-14
@@ -13,14 +13,23 @@ cachedVersions="/etc/pihole/versions"
|
|||||||
|
|
||||||
if [ -f ${cachedVersions} ]; then
|
if [ -f ${cachedVersions} ]; then
|
||||||
# shellcheck source=/dev/null
|
# shellcheck source=/dev/null
|
||||||
. "$cachedVersions"
|
. "${cachedVersions}"
|
||||||
else
|
else
|
||||||
echo "Could not find /etc/pihole/versions. Running update now."
|
echo "Could not find /etc/pihole/versions. Running update now."
|
||||||
pihole updatechecker
|
pihole updatechecker
|
||||||
# shellcheck source=/dev/null
|
# shellcheck source=/dev/null
|
||||||
. "$cachedVersions"
|
. "${cachedVersions}"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Convert "null" or empty values to "N/A" for display
|
||||||
|
normalize_version() {
|
||||||
|
if [ -z "${1}" ] || [ "${1}" = "null" ]; then
|
||||||
|
echo "N/A"
|
||||||
|
else
|
||||||
|
echo "${1}"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
main() {
|
main() {
|
||||||
local details
|
local details
|
||||||
details=false
|
details=false
|
||||||
@@ -33,21 +42,21 @@ main() {
|
|||||||
|
|
||||||
if [ "${details}" = true ]; then
|
if [ "${details}" = true ]; then
|
||||||
echo "Core"
|
echo "Core"
|
||||||
echo " Version is ${CORE_VERSION:=N/A} (Latest: ${GITHUB_CORE_VERSION:=N/A})"
|
echo " Version is $(normalize_version "${CORE_VERSION}") (Latest: $(normalize_version "${GITHUB_CORE_VERSION}"))"
|
||||||
echo " Branch is ${CORE_BRANCH:=N/A}"
|
echo " Branch is $(normalize_version "${CORE_BRANCH}")"
|
||||||
echo " Hash is ${CORE_HASH:=N/A} (Latest: ${GITHUB_CORE_HASH:=N/A})"
|
echo " Hash is $(normalize_version "${CORE_HASH}") (Latest: $(normalize_version "${GITHUB_CORE_HASH}"))"
|
||||||
echo "Web"
|
echo "Web"
|
||||||
echo " Version is ${WEB_VERSION:=N/A} (Latest: ${GITHUB_WEB_VERSION:=N/A})"
|
echo " Version is $(normalize_version "${WEB_VERSION}") (Latest: $(normalize_version "${GITHUB_WEB_VERSION}"))"
|
||||||
echo " Branch is ${WEB_BRANCH:=N/A}"
|
echo " Branch is $(normalize_version "${WEB_BRANCH}")"
|
||||||
echo " Hash is ${WEB_HASH:=N/A} (Latest: ${GITHUB_WEB_HASH:=N/A})"
|
echo " Hash is $(normalize_version "${WEB_HASH}") (Latest: $(normalize_version "${GITHUB_WEB_HASH}"))"
|
||||||
echo "FTL"
|
echo "FTL"
|
||||||
echo " Version is ${FTL_VERSION:=N/A} (Latest: ${GITHUB_FTL_VERSION:=N/A})"
|
echo " Version is $(normalize_version "${FTL_VERSION}") (Latest: $(normalize_version "${GITHUB_FTL_VERSION}"))"
|
||||||
echo " Branch is ${FTL_BRANCH:=N/A}"
|
echo " Branch is $(normalize_version "${FTL_BRANCH}")"
|
||||||
echo " Hash is ${FTL_HASH:=N/A} (Latest: ${GITHUB_FTL_HASH:=N/A})"
|
echo " Hash is $(normalize_version "${FTL_HASH}") (Latest: $(normalize_version "${GITHUB_FTL_HASH}"))"
|
||||||
else
|
else
|
||||||
echo "Core version is ${CORE_VERSION:=N/A} (Latest: ${GITHUB_CORE_VERSION:=N/A})"
|
echo "Core version is $(normalize_version "${CORE_VERSION}") (Latest: $(normalize_version "${GITHUB_CORE_VERSION}"))"
|
||||||
echo "Web version is ${WEB_VERSION:=N/A} (Latest: ${GITHUB_WEB_VERSION:=N/A})"
|
echo "Web version is $(normalize_version "${WEB_VERSION}") (Latest: $(normalize_version "${GITHUB_WEB_VERSION}"))"
|
||||||
echo "FTL version is ${FTL_VERSION:=N/A} (Latest: ${GITHUB_FTL_VERSION:=N/A})"
|
echo "FTL version is $(normalize_version "${FTL_VERSION}") (Latest: $(normalize_version "${GITHUB_FTL_VERSION}"))"
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -188,27 +188,14 @@ PIHOLE_META_DEPS_APK=(
|
|||||||
# The runUnattended flag is one example of this
|
# The runUnattended flag is one example of this
|
||||||
repair=false
|
repair=false
|
||||||
runUnattended=false
|
runUnattended=false
|
||||||
skipFTL=false
|
|
||||||
# Check arguments for the undocumented flags
|
# Check arguments for the undocumented flags
|
||||||
for var in "$@"; do
|
for var in "$@"; do
|
||||||
case "${var}" in
|
case "${var}" in
|
||||||
"--repair") repair=true ;;
|
"--repair") repair=true ;;
|
||||||
"--unattended") runUnattended=true ;;
|
"--unattended") runUnattended=true ;;
|
||||||
"--skipFTL") skipFTL=true ;;
|
|
||||||
esac
|
esac
|
||||||
done
|
done
|
||||||
|
|
||||||
if [[ "${runUnattended}" == true ]]; then
|
|
||||||
# In order to run an unattended setup, a pre-seeded /etc/pihole/pihole.toml must exist
|
|
||||||
if [[ ! -f "${PI_HOLE_CONFIG_DIR}/pihole.toml" ]]; then
|
|
||||||
printf " %b Error: \"%s\" not found. Cannot run unattended setup\\n" "${CROSS}" "${PI_HOLE_CONFIG_DIR}/pihole.toml"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
printf " %b Performing unattended setup, no dialogs will be displayed\\n" "${INFO}"
|
|
||||||
# also disable debconf-apt-progress dialogs
|
|
||||||
export DEBIAN_FRONTEND="noninteractive"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# If the color table file exists,
|
# If the color table file exists,
|
||||||
if [[ -f "${coltable}" ]]; then
|
if [[ -f "${coltable}" ]]; then
|
||||||
# source it
|
# source it
|
||||||
@@ -1963,18 +1950,9 @@ get_binary_name() {
|
|||||||
|
|
||||||
# If the machine is aarch64 (armv8)
|
# If the machine is aarch64 (armv8)
|
||||||
if [[ "${machine}" == "aarch64" ]]; then
|
if [[ "${machine}" == "aarch64" ]]; then
|
||||||
if [[ "$(getconf LONG_BIT)" == "64" ]]; then
|
# If AArch64 is found (e.g., BCM2711 in Raspberry Pi 4)
|
||||||
# If the OS is 64 bit, we use the arm64 binary
|
|
||||||
printf "%b %b Detected AArch64 (64 Bit ARM) architecture\\n" "${OVER}" "${TICK}"
|
printf "%b %b Detected AArch64 (64 Bit ARM) architecture\\n" "${OVER}" "${TICK}"
|
||||||
l_binary="pihole-FTL-arm64"
|
l_binary="pihole-FTL-arm64"
|
||||||
else
|
|
||||||
# If the OS is 32 bit, we use the armv7 binary (aarch64 is actually armv8)
|
|
||||||
# Even though the machine is 64 bit capable, this makes debugging
|
|
||||||
# very hard as 32bit tools like gdb, etc. cannot analyze the 64 bit
|
|
||||||
# binary. See FTL issue #2494 for such an example.
|
|
||||||
printf "%b %b Detected AArch64 (64 Bit ARM) architecture with 32 bit OS\\n" "${OVER}" "${TICK}"
|
|
||||||
l_binary="pihole-FTL-armv7"
|
|
||||||
fi
|
|
||||||
elif [[ "${machine}" == "arm"* ]]; then
|
elif [[ "${machine}" == "arm"* ]]; then
|
||||||
# ARM 32 bit
|
# ARM 32 bit
|
||||||
# Get supported processor from other binaries installed on the system
|
# Get supported processor from other binaries installed on the system
|
||||||
@@ -2344,9 +2322,6 @@ main() {
|
|||||||
|
|
||||||
# Check if there is a usable FTL binary available on this architecture - do
|
# Check if there is a usable FTL binary available on this architecture - do
|
||||||
# this early on as FTL is a hard dependency for Pi-hole
|
# this early on as FTL is a hard dependency for Pi-hole
|
||||||
# Allow the user to skip this check if they are using a self-compiled FTL binary from an unsupported architecture
|
|
||||||
if [ "${skipFTL}" != true ]; then
|
|
||||||
# Get the binary name for the current architecture
|
|
||||||
local funcOutput
|
local funcOutput
|
||||||
funcOutput=$(get_binary_name) #Store output of get_binary_name here
|
funcOutput=$(get_binary_name) #Store output of get_binary_name here
|
||||||
# Abort early if this processor is not supported (get_binary_name returns empty string)
|
# Abort early if this processor is not supported (get_binary_name returns empty string)
|
||||||
@@ -2354,8 +2329,14 @@ main() {
|
|||||||
printf " %b Upgrade/install aborted\\n" "${CROSS}" "${DISTRO_NAME}"
|
printf " %b Upgrade/install aborted\\n" "${CROSS}" "${DISTRO_NAME}"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
else
|
|
||||||
printf " %b %b--skipFTL set - skipping architecture check%b\\n" "${INFO}" "${COL_YELLOW}" "${COL_NC}"
|
if [[ "${fresh_install}" == false ]]; then
|
||||||
|
# if it's running unattended,
|
||||||
|
if [[ "${runUnattended}" == true ]]; then
|
||||||
|
printf " %b Performing unattended setup, no dialogs will be displayed\\n" "${INFO}"
|
||||||
|
# also disable debconf-apt-progress dialogs
|
||||||
|
export DEBIAN_FRONTEND="noninteractive"
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ "${fresh_install}" == true ]]; then
|
if [[ "${fresh_install}" == true ]]; then
|
||||||
@@ -2388,8 +2369,6 @@ main() {
|
|||||||
create_pihole_user
|
create_pihole_user
|
||||||
|
|
||||||
# Download and install FTL
|
# Download and install FTL
|
||||||
# Allow the user to skip this check if they are using a self-compiled FTL binary from an unsupported architecture
|
|
||||||
if [ "${skipFTL}" != true ]; then
|
|
||||||
local binary
|
local binary
|
||||||
binary="pihole-FTL${funcOutput##*pihole-FTL}" #binary name will be the last line of the output of get_binary_name (it always begins with pihole-FTL)
|
binary="pihole-FTL${funcOutput##*pihole-FTL}" #binary name will be the last line of the output of get_binary_name (it always begins with pihole-FTL)
|
||||||
local theRest
|
local theRest
|
||||||
@@ -2398,9 +2377,6 @@ main() {
|
|||||||
printf " %b FTL Engine not installed\\n" "${CROSS}"
|
printf " %b FTL Engine not installed\\n" "${CROSS}"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
else
|
|
||||||
printf " %b %b--skipFTL set - skipping FTL binary installation%b\\n" "${INFO}" "${COL_YELLOW}" "${COL_NC}"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Install and log everything to a file
|
# Install and log everything to a file
|
||||||
installPihole | tee -a /proc/$$/fd/3
|
installPihole | tee -a /proc/$$/fd/3
|
||||||
|
|||||||
+13
-28
@@ -612,7 +612,7 @@ compareLists() {
|
|||||||
gravity_DownloadBlocklistFromUrl() {
|
gravity_DownloadBlocklistFromUrl() {
|
||||||
local url="${1}" adlistID="${2}" saveLocation="${3}" compression="${4}" gravity_type="${5}" domain="${6}"
|
local url="${1}" adlistID="${2}" saveLocation="${3}" compression="${4}" gravity_type="${5}" domain="${6}"
|
||||||
local listCurlBuffer str httpCode success="" ip customUpstreamResolver=""
|
local listCurlBuffer str httpCode success="" ip customUpstreamResolver=""
|
||||||
local file_path ip_addr port blocked=false download=true
|
local file_path permissions ip_addr port blocked=false download=true
|
||||||
# modifiedOptions is an array to store all the options used to check if the adlist has been changed upstream
|
# modifiedOptions is an array to store all the options used to check if the adlist has been changed upstream
|
||||||
local modifiedOptions=()
|
local modifiedOptions=()
|
||||||
|
|
||||||
@@ -721,42 +721,31 @@ gravity_DownloadBlocklistFromUrl() {
|
|||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# If we "download" a local file (file://), verify read access before using it.
|
# If we are going to "download" a local file, we first check if the target
|
||||||
# When running as root (e.g., via pihole -g), check that the 'pihole' user can read the file
|
# file has a+r permission. We explicitly check for all+read because we want
|
||||||
# to match the effective runtime user of FTL; otherwise, check the current user's read access
|
# to make sure that the file is readable by everyone and not just the user
|
||||||
# (e.g., in Docker or when invoked by a non-root user). The target must
|
# running the script.
|
||||||
# resolve to a regular file and be readable by the evaluated user.
|
if [[ $url == "file://"* ]]; then
|
||||||
if [[ "${url}" == "file:/"* ]]; then
|
|
||||||
# Get the file path
|
# Get the file path
|
||||||
file_path=$(echo "${url}" | cut -d'/' -f3-)
|
file_path=$(echo "$url" | cut -d'/' -f3-)
|
||||||
# Check if the file exists and is a regular file (i.e. not a socket, fifo, tty, block). Might still be a symlink.
|
# Check if the file exists and is a regular file (i.e. not a socket, fifo, tty, block). Might still be a symlink.
|
||||||
if [[ ! -f ${file_path} ]]; then
|
if [[ ! -f $file_path ]]; then
|
||||||
# Output that the file does not exist
|
# Output that the file does not exist
|
||||||
echo -e "${OVER} ${CROSS} ${file_path} does not exist"
|
echo -e "${OVER} ${CROSS} ${file_path} does not exist"
|
||||||
download=false
|
download=false
|
||||||
else
|
else
|
||||||
if [ "$(id -un)" == "root" ]; then
|
# Check if the file or a file referenced by the symlink has a+r permissions
|
||||||
# If we are root, we need to check if the pihole user has read permission
|
permissions=$(stat -L -c "%a" "$file_path")
|
||||||
# otherwise, we might read files that the pihole user should not be able to read
|
if [[ $permissions == *4 || $permissions == *5 || $permissions == *6 || $permissions == *7 ]]; then
|
||||||
if sudo -u pihole test -r "${file_path}"; then
|
|
||||||
echo -e "${OVER} ${INFO} Using local file ${file_path}"
|
|
||||||
else
|
|
||||||
echo -e "${OVER} ${CROSS} Cannot read file (user 'pihole' lacks read permission)"
|
|
||||||
download=false
|
|
||||||
fi
|
|
||||||
else
|
|
||||||
# If we are not root, we just check if the current user has read permission
|
|
||||||
if [[ -r "${file_path}" ]]; then
|
|
||||||
# Output that we are using the local file
|
# Output that we are using the local file
|
||||||
echo -e "${OVER} ${INFO} Using local file ${file_path}"
|
echo -e "${OVER} ${INFO} Using local file ${file_path}"
|
||||||
else
|
else
|
||||||
# Output that the file is not readable by the current user
|
# Output that the file does not have the correct permissions
|
||||||
echo -e "${OVER} ${CROSS} Cannot read file (current user '$(id -un)' lacks read permission)"
|
echo -e "${OVER} ${CROSS} Cannot read file (file needs to have a+r permission)"
|
||||||
download=false
|
download=false
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
fi
|
|
||||||
|
|
||||||
# Check for allowed protocols
|
# Check for allowed protocols
|
||||||
if [[ $url != "http"* && $url != "https"* && $url != "file"* && $url != "ftp"* && $url != "ftps"* && $url != "sftp"* ]]; then
|
if [[ $url != "http"* && $url != "https"* && $url != "file"* && $url != "ftp"* && $url != "ftps"* && $url != "sftp"* ]]; then
|
||||||
@@ -822,10 +811,6 @@ gravity_DownloadBlocklistFromUrl() {
|
|||||||
fix_owner_permissions "${saveLocation}"
|
fix_owner_permissions "${saveLocation}"
|
||||||
# Compare lists if they are identical
|
# Compare lists if they are identical
|
||||||
compareLists "${adlistID}" "${saveLocation}"
|
compareLists "${adlistID}" "${saveLocation}"
|
||||||
# Set permissions for the *.etag file
|
|
||||||
if [[ -f "${saveLocation}.etag" ]]; then
|
|
||||||
fix_owner_permissions "${saveLocation}.etag"
|
|
||||||
fi
|
|
||||||
# Add domains to database table file
|
# Add domains to database table file
|
||||||
pihole-FTL "${gravity_type}" parseList "${saveLocation}" "${gravityTEMPfile}" "${adlistID}"
|
pihole-FTL "${gravity_type}" parseList "${saveLocation}" "${gravityTEMPfile}" "${adlistID}"
|
||||||
done="true"
|
done="true"
|
||||||
|
|||||||
@@ -125,22 +125,7 @@ repairPiholeFunc() {
|
|||||||
if [ -n "${DOCKER_VERSION}" ]; then
|
if [ -n "${DOCKER_VERSION}" ]; then
|
||||||
unsupportedFunc
|
unsupportedFunc
|
||||||
else
|
else
|
||||||
local skipFTL additionalFlag
|
/etc/.pihole/automated\ install/basic-install.sh --repair
|
||||||
skipFTL=false
|
|
||||||
# Check arguments
|
|
||||||
for var in "$@"; do
|
|
||||||
case "$var" in
|
|
||||||
"--skipFTL") skipFTL=true ;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
|
|
||||||
if [ "${skipFTL}" == true ]; then
|
|
||||||
additionalFlag="--skipFTL"
|
|
||||||
else
|
|
||||||
additionalFlag=""
|
|
||||||
fi
|
|
||||||
|
|
||||||
/etc/.pihole/automated\ install/basic-install.sh --repair ${additionalFlag}
|
|
||||||
exit 0;
|
exit 0;
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
@@ -616,7 +601,7 @@ case "${1}" in
|
|||||||
"-d" | "debug" ) debugFunc "$@";;
|
"-d" | "debug" ) debugFunc "$@";;
|
||||||
"-f" | "flush" ) flushFunc "$@";;
|
"-f" | "flush" ) flushFunc "$@";;
|
||||||
"-up" | "updatePihole" ) updatePiholeFunc "$@";;
|
"-up" | "updatePihole" ) updatePiholeFunc "$@";;
|
||||||
"-r" | "repair" ) repairPiholeFunc "$@";;
|
"-r" | "repair" ) repairPiholeFunc;;
|
||||||
"-g" | "updateGravity" ) updateGravityFunc "$@";;
|
"-g" | "updateGravity" ) updateGravityFunc "$@";;
|
||||||
"-l" | "logging" ) piholeLogging "$@";;
|
"-l" | "logging" ) piholeLogging "$@";;
|
||||||
"uninstall" ) uninstallFunc;;
|
"uninstall" ) uninstallFunc;;
|
||||||
|
|||||||
Reference in New Issue
Block a user