From 1c03d0506ce5923c5af34b1097836aa39313a54c Mon Sep 17 00:00:00 2001 From: "CanbiZ (MickLesk)" <47820557+MickLesk@users.noreply.github.com> Date: Wed, 5 Aug 2026 14:04:16 +0200 Subject: [PATCH] NextcloudPI: Bump to Debian Trixie & Tweak broken SSH (#15957) * Pin NextCloudPi installer to last known-good stable release The floating "master" branch of nextcloud/nextcloudpi's install.sh started rejecting our default Debian 12 base with "distro not supported" (#15944) after a regression landed upstream; the script is third-party code we don't audit or control. Pin to v1.57.1, the latest stable (non-prerelease) release, which explicitly targets Debian bookworm and predates the regression. * Actually pin the branch nextcloudpi's install.sh clones internally install.sh is only a thin bootstrapper: it clones BRANCH (default "master") of the nextcloudpi repo itself and runs the real installer from that fresh checkout, including the distro-support check. Fetching install.sh from a pinned tag alone left BRANCH defaulting to "master", so the internally-cloned code was unaffected and still failed with "distro not supported" - confirmed by testing the previous fix. Pass BRANCH explicitly so the internal clone also targets the pinned tag. * Bump NextCloudPi to Debian 13, matching upstream's trixie move Upstream's master ncp.cfg now targets release "trixie" (Debian 13); bookworm (Debian 12) is no longer in the supported check_distro list at all. Move our own default to Debian 13 and pin the installer ref to v1.58.0-rc1, the only tagged ref with release=trixie so far (no stable trixie release exists yet upstream). * Revert installer pin, track master again master now targets trixie itself (matches the Debian 13 bump), and the only tagged trixie ref was an RC explicitly marked "expect bugs". Tracking master gets upstream trixie fixes as they land instead of being stuck on a stale test release. * Work around nextcloudpi's broken ssh.socket restart on Debian 13 Debian 13's openssh-server ships socket-activated by default. NCP's own bin/ncp/NETWORKING/SSH.sh detects that (systemctl is-active ssh.socket) but then runs "systemctl restart ssh" in that branch instead of reloading, which collides with the port ssh.socket already holds and fails with "Job for ssh.service failed" (#15944). Switch the container to classic ssh.service before handing off to their installer so it takes the safe "systemctl reload ssh" branch instead. --- ct/nextcloudpi.sh | 2 +- install/nextcloudpi-install.sh | 5 +++++ 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/ct/nextcloudpi.sh b/ct/nextcloudpi.sh index 812e72fa6..5baaf156d 100644 --- a/ct/nextcloudpi.sh +++ b/ct/nextcloudpi.sh @@ -11,7 +11,7 @@ var_cpu="${var_cpu:-2}" var_ram="${var_ram:-2048}" var_disk="${var_disk:-8}" var_os="${var_os:-debian}" -var_version="${var_version:-12}" +var_version="${var_version:-13}" var_arm64="${var_arm64:-yes}" var_unprivileged="${var_unprivileged:-1}" diff --git a/install/nextcloudpi-install.sh b/install/nextcloudpi-install.sh index 1b30a173b..5e71d55d2 100644 --- a/install/nextcloudpi-install.sh +++ b/install/nextcloudpi-install.sh @@ -24,6 +24,11 @@ if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then exit 10 fi +msg_info "Switching SSH to classic (non-socket-activated) mode" +systemctl disable --now ssh.socket &>/dev/null || true +systemctl enable --now ssh &>/dev/null || true +msg_ok "Switched SSH to classic mode" + msg_info "Installing NextCloudPi (Patience)" $STD bash <(curl -fsSL https://raw.githubusercontent.com/nextcloud/nextcloudpi/master/install.sh) msg_ok "Installed NextCloudPi"