Used REGEX for composition sync

This commit is contained in:
m8in
2026-06-19 22:38:54 +02:00
parent 478d298b16
commit ffebc8c66e
4 changed files with 13 additions and 12 deletions
+3 -3
View File
@@ -23,9 +23,9 @@ function base.checkAllInputParameters() {
_SUCCESS="true" _SUCCESS="true"
for _ARG in "${@}"; do for _ARG in "${@}"; do
if [ -n "${_ARG}" ]; then if [ -n "${_ARG}" ]; then
# Has to start with an alphanumeric char '--' or '/' # Has to start with an alphanumeric char '--', '/' or '@'
if [[ ! "${_ARG}" =~ ^(--|/)?[[:alnum:]] ]]; then if [[ ! "${_ARG}" =~ ^(--|/|@)?[[:alnum:]] ]]; then
echo "❌ Security base.checkAllInputParameters(): No special characters except '--' or '/' are allowed at the beginning of a parameter: '${_ARG}'" >&2 echo "❌ Security base.checkAllInputParameters(): No special characters except '--', '/' or '@' are allowed at the beginning of a parameter: '${_ARG}'" >&2
_SUCCESS="false" _SUCCESS="false"
fi fi
# No forbidden character is allowed to remain # No forbidden character is allowed to remain
@@ -6,6 +6,6 @@ Cmnd_Alias C_COMPOSITION_SYNC = \
^[a-zA-Z0-9][a-zA-Z0-9.-]* \ ^[a-zA-Z0-9][a-zA-Z0-9.-]* \
[a-zA-Z][a-zA-Z0-9/_-]*[a-zA-Z0-9] \ [a-zA-Z][a-zA-Z0-9/_-]*[a-zA-Z0-9] \
[a-zA-Z0-9][a-zA-Z0-9_-]* \ [a-zA-Z0-9][a-zA-Z0-9_-]* \
([a-zA-Z0-9][a-zA-Z0-9._:-]*)? \ (@[a-zA-Z0-9][a-zA-Z0-9._:-]*)? \
([a-zA-Z0-9][a-zA-Z0-9._:-]*)?$ ([a-zA-Z0-9][a-zA-Z0-9._:-]*)?$
composition-sync ALL = (root) NOPASSWD: C_COMPOSITION_SYNC composition-sync ALL = (root) NOPASSWD: C_COMPOSITION_SYNC
@@ -130,14 +130,14 @@ function send() {
# Parameter 3: Only alphanumeric characters allowed and [.-] if not leading (due to: -oProxyCommand=...). # Parameter 3: Only alphanumeric characters allowed and [.-] if not leading (due to: -oProxyCommand=...).
# Parameter 4: Only alphanumeric characters allowed and [._:-] if not leading (due to: -oProxyCommand=...), but can be empty. # Parameter 4: Only alphanumeric characters allowed and [._:-] if not leading (due to: -oProxyCommand=...), but can be empty.
# Parameter 5: Only alphanumeric characters allowed and [._:-] if not leading (due to: -oProxyCommand=...), but can be empty. # Parameter 5: Only alphanumeric characters allowed and [._:-] if not leading (due to: -oProxyCommand=...), but can be empty.
base.set RECEIVERHOST "${1}" '^[a-zA-Z0-9][a-zA-Z0-9._-]*$' base.set RECEIVERHOST "${1}" "${REGEX[HOST]}"
base.set ZFS_BRANCH "${2}" '^[a-zA-Z][a-zA-Z0-9/_-]*[a-zA-Z0-9]$' base.set ZFS_BRANCH "${2}" "${REGEX[ZFS]}"
base.set COMPOSITION "${3}" '^[a-zA-Z0-9][a-zA-Z0-9.-]*$' base.set COMPOSITION "${3}" "${REGEX[COMPOSITION]}"
base.set RECEIVERS_SNAPSHOT "${4}" '^[a-zA-Z0-9][a-zA-Z0-9._:-]*$' optional base.set RECEIVERS_SNAPSHOT "${4}" "${REGEX[SNAPSHOT]}" optional
base.set RESUME_TOKEN "${5}" '^[a-zA-Z0-9][a-zA-Z0-9._:-]*$' optional base.set RESUME_TOKEN "${5}" '^[a-zA-Z0-9][a-zA-Z0-9._:-]*$' optional
# Resume mode # Resume mode
if [ "${RECEIVERS_SNAPSHOT}" == "RESUME" ]; then if [ "${RECEIVERS_SNAPSHOT}" == "@RESUME" ] && [ -n "${RESUME_TOKEN}" ]; then
sendResume "${RESUME_TOKEN}" sendResume "${RESUME_TOKEN}"
# Exit preserving the code # Exit preserving the code
+4 -3
View File
@@ -108,7 +108,7 @@ function receive() {
_RESUME_TOKEN=$(zfs get -H -o value receive_resume_token "${_ZFS}" 2> /dev/null) _RESUME_TOKEN=$(zfs get -H -o value receive_resume_token "${_ZFS}" 2> /dev/null)
if [ -n "${_RESUME_TOKEN}" ] && [ "${_RESUME_TOKEN}" != "-" ]; then if [ -n "${_RESUME_TOKEN}" ] && [ "${_RESUME_TOKEN}" != "-" ]; then
echo "Resume token present trying to resume at ${_RESUME_TOKEN}" echo "Resume token present trying to resume at ${_RESUME_TOKEN}"
_COMMON_SNAPSHOT="RESUME" _COMMON_SNAPSHOT="@RESUME"
else else
_RESUME_TOKEN="" _RESUME_TOKEN=""
_COMMON_SNAPSHOT=$(zfs list -H -o name -S creation -t snapshot "${_ZFS}" 2> /dev/null | head -n 1) _COMMON_SNAPSHOT=$(zfs list -H -o name -S creation -t snapshot "${_ZFS}" 2> /dev/null | head -n 1)
@@ -118,13 +118,14 @@ function receive() {
fi fi
# Add "-s" for resumable streams in the next line at zfs receive. Not done yet because of: cannot receive resume stream: kernel modules must be upgraded to receive this stream. # Add "-s" for resumable streams in the next line at zfs receive. Not done yet because of: cannot receive resume stream: kernel modules must be upgraded to receive this stream.
${_SSH_COMMAND} "sudo ${_SEND_SCRIPT:?"Missing SEND_SCRIPT"} \"${_RECEIVERHOST}\" \"${_ZFS_BRANCH}\" \"${_COMPOSITION}\" \"${_COMMON_SNAPSHOT#${_ZFS}@}\" \"${_RESUME_TOKEN}\"" | zfs receive -v "${_ZFS}" ${_SSH_COMMAND} "sudo ${_SEND_SCRIPT:?"Missing SEND_SCRIPT"} \"${_RECEIVERHOST}\" \"${_ZFS_BRANCH}\" \"${_COMPOSITION}\" \"@${_COMMON_SNAPSHOT#*@}\" \"${_RESUME_TOKEN}\"" | zfs receive -v "${_ZFS}"
if [ $? -ne 0 ]; then if [ $? -ne 0 ]; then
echo "Unable to receive stream using these settings:" echo "Unable to receive stream using these settings:"
echo " - Sending host: ${_SOURCEHOST}:${_SSH_PORT}" echo " - Sending host: ${_SOURCEHOST}:${_SSH_PORT}"
echo " - Receiving host: ${_RECEIVERHOST}" echo " - Receiving host: ${_RECEIVERHOST}"
echo " - ZFS Branch: ${_ZFS_BRANCH}"
echo " - Composition: ${_COMPOSITION}" echo " - Composition: ${_COMPOSITION}"
echo " - Offered snapshot: ${_ZFS}@${_COMMON_SNAPSHOT#${_ZFS}@}" echo " - Offered snapshot: @${_COMMON_SNAPSHOT#*@}"
echo " - Resume token: ${_RESUME_TOKEN}" echo " - Resume token: ${_RESUME_TOKEN}"
echo "Current state of snapshots:" echo "Current state of snapshots:"
zfs list -t snapshot "${_ZFS}" 2> /dev/null | tail zfs list -t snapshot "${_ZFS}" 2> /dev/null | tail