#!/bin/sh # Configure jray-server from the debconf answers. # # /etc/jray-server/env is deliberately NOT a dpkg conffile. A conffile is for a # file the package ships and the operator may edit; this one is *generated* from # debconf, so shipping it would make dpkg prompt on every upgrade about changes # the package itself had made. Instead it is written here and updated key by # key, which leaves comments, ordering and any setting debconf does not manage # untouched. set -e . /usr/share/debconf/confmodule CONF_DIR=/etc/jray-server ENV_FILE="$CONF_DIR/env" # Update one KEY=value in place, appending if absent. Everything else in the # file - comments, blank lines, settings this package does not ask about - is # preserved, which is what makes hand-editing and dpkg-reconfigure coexist. set_kv() { key="$1"; val="$2" if grep -q "^$key=" "$ENV_FILE" 2>/dev/null; then # `|` as the delimiter: values are hostnames, IP lists and URLs, none of # which contain it, whereas `/` appears in contacts and base URLs. sed -i "s|^$key=.*|$key=$val|" "$ENV_FILE" else printf '%s=%s\n' "$key" "$val" >> "$ENV_FILE" fi } case "$1" in configure) mkdir -p "$CONF_DIR" chmod 0755 "$CONF_DIR" if [ ! -f "$ENV_FILE" ]; then cat > "$ENV_FILE" <<'EOF' # jray-server configuration. # # Written by the package from your debconf answers; re-run # dpkg-reconfigure jray-server # to change them. Hand edits to this file are preserved: the package updates # only the keys it manages and leaves everything else alone. # # The full set of variables is in SPEC.md section 8 and src/config.rs. EOF fi # 0600 before anything is written into it: the TMDB key lands here. chmod 0600 "$ENV_FILE" db_get jray-server/server-id && set_kv JRAY_SERVER_ID "$RET" db_get jray-server/bind && set_kv JRAY_BIND "$RET" db_get jray-server/trusted-proxies && set_kv JRAY_TRUSTED_PROXIES "$RET" db_get jray-server/contact && set_kv JRAY_CONTACT "$RET" db_get jray-server/publish-peer-directory if [ "$RET" = "true" ]; then set_kv JRAY_PUBLISH_PEER_DIRECTORY 1 else set_kv JRAY_PUBLISH_PEER_DIRECTORY 0 fi # Blank means "keep whatever is already configured" - see the note in the # debconf template. Only overwrite when the operator actually supplied one. db_get jray-server/tmdb-api-key if [ -n "$RET" ]; then set_kv JRAY_TMDB_API_KEY "$RET" elif ! grep -q '^JRAY_TMDB_API_KEY=' "$ENV_FILE" 2>/dev/null; then set_kv JRAY_TMDB_API_KEY "" fi # Drop the secret from debconf's database now that it is in the env file. # config.dat is root-only, so this is defence in depth rather than a fix for # a leak - but there is no reason for a second copy to outlive its use. db_set jray-server/tmdb-api-key "" || true set_kv JRAY_DB "/var/lib/jray-server/jray.db" # Warn about the two settings whose absence fails silently rather than # loudly. Both are recoverable with dpkg-reconfigure, and neither stops the # service starting, so the operator would otherwise find out from a log line # they had no reason to read. if ! grep -q '^JRAY_TMDB_API_KEY=.' "$ENV_FILE" 2>/dev/null; then echo "jray-server: no TMDB API key set - uploads will stay pending and never be listed." >&2 echo " Set one with: dpkg-reconfigure jray-server" >&2 fi if ! grep -q '^JRAY_TRUSTED_PROXIES=.' "$ENV_FILE" 2>/dev/null; then echo "jray-server: no trusted proxies set - X-Forwarded-For will be ignored, so every" >&2 echo " client shares one rate-limit bucket. Set your proxy's address with:" >&2 echo " dpkg-reconfigure jray-server" >&2 fi ;; abort-upgrade|abort-remove|abort-deconfigure) ;; *) echo "postinst called with unknown argument \`$1'" >&2; exit 1 ;; esac # systemd wiring, in the form dh_installsystemd generates. StateDirectory= in the # unit creates and owns /var/lib/jray-server, so there is no directory or user to # set up here. if [ "$1" = "configure" ] || [ "$1" = "abort-upgrade" ]; then if [ -d /run/systemd/system ]; then systemctl --system daemon-reload >/dev/null 2>&1 || true fi if deb-systemd-helper debian-installed jray-server.service 2>/dev/null; then deb-systemd-helper unmask jray-server.service >/dev/null || true if deb-systemd-helper --quiet was-enabled jray-server.service; then deb-systemd-helper enable jray-server.service >/dev/null || true else deb-systemd-helper update-state jray-server.service >/dev/null || true fi fi if [ -d /run/systemd/system ]; then # Starting an unconfigured install is safe by construction: JRAY_BIND # defaults to loopback, so it is not reachable until the operator says # otherwise. deb-systemd-invoke restart jray-server.service >/dev/null || true fi fi exit 0