Compare commits

..

2 Commits

Author SHA1 Message Date
CanbiZ (MickLesk) 7d5e1e04ae Update misc/tools.func
Co-authored-by: Sam Heinz <sam@samheinz.com>
2026-08-06 13:15:57 +02:00
MickLesk 71da6d96dc setup_nodejs: bypass npm allowScripts policy globally on npm >=11 2026-08-04 23:13:12 +02:00
23 changed files with 84 additions and 313 deletions
+1 -39
View File
@@ -518,54 +518,16 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details> </details>
## 2026-08-06
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- paperless: change update abort message (endless spinner) [@MickLesk](https://github.com/MickLesk) ([#16299](https://github.com/community-scripts/ProxmoxVE/pull/16299))
- #### ✨ New Features
- Vikunja: remove version pin, v2.5.0 fixes the systemd syscall filter crash [@MickLesk](https://github.com/MickLesk) ([#16300](https://github.com/community-scripts/ProxmoxVE/pull/16300))
### 💾 Core
- #### 🔧 Refactor
- build.func: filter templates by host architecture during search [@MickLesk](https://github.com/MickLesk) ([#16302](https://github.com/community-scripts/ProxmoxVE/pull/16302))
## 2026-08-05
### 🚀 Updated Scripts
- #### ✨ New Features
- NextcloudPI: Bump to Debian Trixie & Tweak broken SSH [@MickLesk](https://github.com/MickLesk) ([#15957](https://github.com/community-scripts/ProxmoxVE/pull/15957))
### 🧰 Tools
- #### 🐞 Bug Fixes
- fix(monitor-all): reduce polling CPU overhead [@jomplox](https://github.com/jomplox) ([#15907](https://github.com/community-scripts/ProxmoxVE/pull/15907))
## 2026-08-04 ## 2026-08-04
### 🆕 New Scripts ### 🆕 New Scripts
- Hister ([#16259](https://github.com/community-scripts/ProxmoxVE/pull/16259)) - Obsidian-LiveSync ([#16233](https://github.com/community-scripts/ProxmoxVE/pull/16233))
- Obsidian-LiveSync ([#16233](https://github.com/community-scripts/ProxmoxVE/pull/16233))
### 🚀 Updated Scripts ### 🚀 Updated Scripts
- #### 🐞 Bug Fixes - #### 🐞 Bug Fixes
- Actual Budget: allow native module install scripts under npm 11 (Node24) [@MickLesk](https://github.com/MickLesk) ([#16277](https://github.com/community-scripts/ProxmoxVE/pull/16277))
- Heimdall-Dashboard: run full composer install on update, force production env [@MickLesk](https://github.com/MickLesk) ([#16278](https://github.com/community-scripts/ProxmoxVE/pull/16278))
- xyOps: rebuild xySat satellite during update [@MickLesk](https://github.com/MickLesk) ([#16279](https://github.com/community-scripts/ProxmoxVE/pull/16279))
- HAOS: remove non-ASCII dash from CPU model dialog text [@MickLesk](https://github.com/MickLesk) ([#16276](https://github.com/community-scripts/ProxmoxVE/pull/16276))
- fix: back up Termix db/data so the update stops destroying encryption keys [@LukeGus](https://github.com/LukeGus) ([#16275](https://github.com/community-scripts/ProxmoxVE/pull/16275))
- passwordpusher: dynamically read Ruby version from .ruby-version file [@Copilot](https://github.com/Copilot) ([#16242](https://github.com/community-scripts/ProxmoxVE/pull/16242)) - passwordpusher: dynamically read Ruby version from .ruby-version file [@Copilot](https://github.com/Copilot) ([#16242](https://github.com/community-scripts/ProxmoxVE/pull/16242))
- fix(salt): write version cache to ~/.salt, not /~.salt [@TowyTowy](https://github.com/TowyTowy) ([#16265](https://github.com/community-scripts/ProxmoxVE/pull/16265)) - fix(salt): write version cache to ~/.salt, not /~.salt [@TowyTowy](https://github.com/TowyTowy) ([#16265](https://github.com/community-scripts/ProxmoxVE/pull/16265))
- AFFiNE: fix version and build type reported by the app itself [@MickLesk](https://github.com/MickLesk) ([#16251](https://github.com/community-scripts/ProxmoxVE/pull/16251)) - AFFiNE: fix version and build type reported by the app itself [@MickLesk](https://github.com/MickLesk) ([#16251](https://github.com/community-scripts/ProxmoxVE/pull/16251))
-2
View File
@@ -39,9 +39,7 @@ function update_script() {
msg_ok "Stopped Service" msg_ok "Stopped Service"
msg_info "Updating Actual Budget to ${RELEASE}" msg_info "Updating Actual Budget to ${RELEASE}"
$STD npm config set allow-scripts=bcrypt,better-sqlite3,argon2 --location=global
$STD npm update -g @actual-app/sync-server $STD npm update -g @actual-app/sync-server
$STD npm rebuild -g
echo "${RELEASE}" >~/.actualbudget echo "${RELEASE}" >~/.actualbudget
msg_ok "Updated Actual Budget to ${RELEASE}" msg_ok "Updated Actual Budget to ${RELEASE}"
-6
View File
@@ -1,6 +0,0 @@
__ ___ __
/ / / (_)____/ /____ _____
/ /_/ / / ___/ __/ _ \/ ___/
/ __ / (__ ) /_/ __/ /
/_/ /_/_/____/\__/\___/_/
+1 -4
View File
@@ -46,11 +46,8 @@ function update_script() {
msg_info "Updating Heimdall-Dashboard" msg_info "Updating Heimdall-Dashboard"
cd /opt/Heimdall cd /opt/Heimdall
sed -i 's/^APP_ENV=.*/APP_ENV=production/' .env
rm -f bootstrap/cache/*.php
export COMPOSER_ALLOW_SUPERUSER=1 export COMPOSER_ALLOW_SUPERUSER=1
$STD composer install --no-dev --no-interaction --prefer-dist --optimize-autoloader $STD composer dump-autoload
$STD php artisan optimize:clear
msg_ok "Updated Heimdall-Dashboard" msg_ok "Updated Heimdall-Dashboard"
msg_info "Restoring Data" msg_info "Restoring Data"
-55
View File
@@ -1,55 +0,0 @@
#!/usr/bin/env bash
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/build.func)
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/asciimoo/hister
APP="Hister"
var_tags="${var_tags:-search;browser-history;personal}"
var_cpu="${var_cpu:-1}"
var_ram="${var_ram:-1024}"
var_disk="${var_disk:-20}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /usr/local/bin/hister ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "hister" "asciimoo/hister"; then
msg_info "Stopping Service"
systemctl stop hister
msg_ok "Stopped Service"
fetch_and_deploy_gh_release "hister" "asciimoo/hister" "singlefile" "latest" "/usr/local/bin" "hister_*_linux_$(arch_resolve)"
msg_info "Starting Service"
systemctl start hister
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:4433${CL}"
+1 -1
View File
@@ -11,7 +11,7 @@ var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-2048}" var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}" var_disk="${var_disk:-8}"
var_os="${var_os:-debian}" var_os="${var_os:-debian}"
var_version="${var_version:-13}" var_version="${var_version:-12}"
var_arm64="${var_arm64:-yes}" var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}" var_unprivileged="${var_unprivileged:-1}"
+1 -1
View File
@@ -65,7 +65,7 @@ function update_script() {
read -rp "Do you want to continue with the update? (y/N): " MIGRATE read -rp "Do you want to continue with the update? (y/N): " MIGRATE
echo echo
if [[ ! "$MIGRATE" =~ ^[Yy]$ ]]; then if [[ ! "$MIGRATE" =~ ^[Yy]$ ]]; then
msg_custom "⚠️" "Update aborted. Decrypt all documents before upgrading to v3." msg_info "Update aborted. Decrypt all documents before upgrading to v3."
exit 0 exit 0
fi fi
fi fi
+10 -38
View File
@@ -112,33 +112,14 @@ EOF
msg_ok "Stopped Termix" msg_ok "Stopped Termix"
msg_info "Migrating Configuration" msg_info "Migrating Configuration"
mkdir -p /opt/termix/db/data if [[ ! -f /opt/termix/.env ]]; then
cat <<EOF >/opt/termix/.env
if [[ -f /opt/termix/data/db.sqlite.encrypted && ! -f /opt/termix/db/data/db.sqlite.encrypted ]]; then
cp -a /opt/termix/data/db.sqlite.encrypted /opt/termix/db/data/db.sqlite.encrypted
[[ -f /opt/termix/data/db.sqlite.encrypted.meta ]] &&
cp -a /opt/termix/data/db.sqlite.encrypted.meta /opt/termix/db/data/db.sqlite.encrypted.meta
[[ -f /opt/termix/data/db.sqlite ]] &&
cp -a /opt/termix/data/db.sqlite /opt/termix/db/data/db.sqlite
fi
if [[ -f /opt/termix/data/.env && ! -f /opt/termix/db/data/.env ]]; then
cp -a /opt/termix/data/.env /opt/termix/db/data/.env
fi
for sub in ssl session_logs session_recordings acme-webroot certbot uploads; do
if [[ -d /opt/termix/data/$sub && ! -d /opt/termix/db/data/$sub ]]; then
cp -a "/opt/termix/data/$sub" "/opt/termix/db/data/$sub"
fi
done
cat <<EOF >/opt/termix/.env
NODE_ENV=production NODE_ENV=production
DATA_DIR=/opt/termix/db/data DATA_DIR=/opt/termix/data
GUACD_HOST=127.0.0.1 GUACD_HOST=127.0.0.1
GUACD_PORT=4822 GUACD_PORT=4822
EOF EOF
fi
if ! grep -q "EnvironmentFile" /etc/systemd/system/termix.service 2>/dev/null; then if ! grep -q "EnvironmentFile" /etc/systemd/system/termix.service 2>/dev/null; then
cat <<EOF >/etc/systemd/system/termix.service cat <<EOF >/etc/systemd/system/termix.service
[Unit] [Unit]
@@ -162,11 +143,7 @@ EOF
fi fi
msg_ok "Migrated Configuration" msg_ok "Migrated Configuration"
create_backup \ create_backup /opt/termix/data /opt/termix/uploads /opt/termix/.env
/opt/termix/db/data \
/opt/termix/data \
/opt/termix/uploads \
/opt/termix/.env
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "termix" "Termix-SSH/Termix" "tarball" CLEAN_INSTALL=1 fetch_and_deploy_gh_release "termix" "Termix-SSH/Termix" "tarball"
@@ -181,10 +158,10 @@ EOF
/opt/termix/db/data /opt/termix/db/data
msg_ok "Recreated Directories" msg_ok "Recreated Directories"
if [[ -f /opt/termix/db/data/db.sqlite.encrypted && ! -f /opt/termix/db/data/.env ]]; then if [[ -f /opt/termix/data/db.sqlite.encrypted && ! -f /opt/termix/db/data/db.sqlite.encrypted ]]; then
msg_error "Encrypted database restored without its keys (/opt/termix/db/data/.env is missing)" msg_info "Migrating Database to new layout"
msg_custom "🛟" "Restore the container from a backup and report this at https://github.com/community-scripts/ProxmoxVE/issues" cp -a /opt/termix/data/db.sqlite.encrypted /opt/termix/db/data/db.sqlite.encrypted
exit 1 msg_ok "Migrated Database to new layout"
fi fi
msg_info "Building Frontend" msg_info "Building Frontend"
@@ -260,12 +237,7 @@ EOF
fi fi
msg_info "Starting Termix" msg_info "Starting Termix"
systemctl daemon-reload systemctl start termix
if ! systemctl start termix; then
msg_error "Termix failed to start"
journalctl -u termix -n 30 --no-pager || true
exit 1
fi
msg_ok "Started Termix" msg_ok "Started Termix"
msg_ok "Updated successfully!" msg_ok "Updated successfully!"
fi fi
+3 -2
View File
@@ -46,7 +46,8 @@ function update_script() {
[[ "$CONFIRM2" =~ ^[yY]$ ]] || exit 0 [[ "$CONFIRM2" =~ ^[yY]$ ]] || exit 0
fi fi
if check_for_gh_release "vikunja" "go-vikunja/vikunja"; then RELEASE="v2.3.0"
if check_for_gh_release "vikunja" "go-vikunja/vikunja" "${RELEASE}" "v2.4.0 is killed at startup by the systemd SystemCallFilter shipped in the .deb (upstream go-vikunja/vikunja#3252); pinned until a fixed release is out"; then
echo echo
msg_warn "The package update may include config file changes." msg_warn "The package update may include config file changes."
echo -e "${TAB}${YW}How do you want to handle /etc/vikunja/config.yml?${CL}" echo -e "${TAB}${YW}How do you want to handle /etc/vikunja/config.yml?${CL}"
@@ -65,7 +66,7 @@ function update_script() {
systemctl stop vikunja systemctl stop vikunja
msg_ok "Stopped Service" msg_ok "Stopped Service"
fetch_and_deploy_gh_release "vikunja" "go-vikunja/vikunja" "binary" "latest" "" "vikunja-*-$(arch_resolve "x86_64" "aarch64").deb" fetch_and_deploy_gh_release "vikunja" "go-vikunja/vikunja" "binary" "${RELEASE}" "" "vikunja-*-$(arch_resolve "x86_64" "aarch64").deb"
$STD systemctl daemon-reload $STD systemctl daemon-reload
msg_info "Starting Service" msg_info "Starting Service"
-7
View File
@@ -48,13 +48,6 @@ function update_script() {
chmod 644 /opt/xyops/node_modules/useragent-ng/lib/regexps.js chmod 644 /opt/xyops/node_modules/useragent-ng/lib/regexps.js
msg_ok "Rebuilt Application" msg_ok "Rebuilt Application"
fetch_and_deploy_gh_release "xysat" "pixlcore/xysat" "tarball" "latest" "/opt/xyops/satellite"
msg_info "Building xySat Satellite"
cd /opt/xyops/satellite
$STD npm install
msg_ok "Built xySat Satellite"
msg_info "Starting Service" msg_info "Starting Service"
systemctl start xyops systemctl start xyops
msg_ok "Started Service" msg_ok "Started Service"
-1
View File
@@ -51,7 +51,6 @@ cat <<EOF >/opt/actualbudget-data/config.json
EOF EOF
mkdir -p /opt/actualbudget mkdir -p /opt/actualbudget
cd /opt/actualbudget cd /opt/actualbudget
$STD npm config set allow-scripts=bcrypt,better-sqlite3,argon2 --location=global
$STD npm install --location=global @actual-app/sync-server $STD npm install --location=global @actual-app/sync-server
echo "${RELEASE}" >~/.actualbudget echo "${RELEASE}" >~/.actualbudget
msg_ok "Installed Actual Budget" msg_ok "Installed Actual Budget"
-1
View File
@@ -24,7 +24,6 @@ fetch_and_deploy_gh_release "Heimdall" "linuxserver/Heimdall" "tarball"
msg_info "Setting up Heimdall-Dashboard" msg_info "Setting up Heimdall-Dashboard"
cd /opt/Heimdall cd /opt/Heimdall
cp .env.example .env cp .env.example .env
sed -i 's/^APP_ENV=.*/APP_ENV=production/' .env
$STD php artisan key:generate $STD php artisan key:generate
msg_ok "Setup Heimdall-Dashboard" msg_ok "Setup Heimdall-Dashboard"
-51
View File
@@ -1,51 +0,0 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/asciimoo/hister
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
fetch_and_deploy_gh_release "hister" "asciimoo/hister" "singlefile" "latest" "/usr/local/bin" "hister_*_linux_$(arch_resolve)"
msg_info "Configuring Hister"
mkdir -p /opt/hister/data /etc/hister
LOCAL_IP=$(hostname -I | awk '{print $1}')
cat <<EOF >/etc/hister/config.yaml
app:
directory: '/opt/hister/data'
server:
address: '0.0.0.0:4433'
base_url: 'http://${LOCAL_IP}:4433'
EOF
msg_ok "Configured Hister"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/hister.service
[Unit]
Description=Hister Search Engine
After=network.target
[Service]
Type=simple
User=root
ExecStart=/usr/local/bin/hister listen --config /etc/hister/config.yaml
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now hister
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc
-10
View File
@@ -24,16 +24,6 @@ if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
exit 10 exit 10
fi fi
msg_info "Making ssh.service reloads behave like restarts"
mkdir -p /etc/systemd/system/ssh.service.d
cat <<'EOF' >/etc/systemd/system/ssh.service.d/reload-as-restart.conf
[Service]
ExecReload=
ExecReload=/usr/bin/systemd-run --no-block --quiet /bin/systemctl restart ssh.service
EOF
systemctl daemon-reload
msg_ok "Made ssh.service reloads behave like restarts"
msg_info "Installing NextCloudPi (Patience)" msg_info "Installing NextCloudPi (Patience)"
$STD bash <(curl -fsSL https://raw.githubusercontent.com/nextcloud/nextcloudpi/master/install.sh) $STD bash <(curl -fsSL https://raw.githubusercontent.com/nextcloud/nextcloudpi/master/install.sh)
msg_ok "Installed NextCloudPi" msg_ok "Installed NextCloudPi"
+1 -1
View File
@@ -125,7 +125,7 @@ EOF
cat <<EOF >/opt/termix/.env cat <<EOF >/opt/termix/.env
NODE_ENV=production NODE_ENV=production
DATA_DIR=/opt/termix/db/data DATA_DIR=/opt/termix/data
GUACD_HOST=127.0.0.1 GUACD_HOST=127.0.0.1
GUACD_PORT=4822 GUACD_PORT=4822
EOF EOF
+2 -1
View File
@@ -13,7 +13,8 @@ setting_up_container
network_check network_check
update_os update_os
fetch_and_deploy_gh_release "vikunja" "go-vikunja/vikunja" "binary" "latest" "" "vikunja-*-$(arch_resolve "x86_64" "aarch64").deb" RELEASE="v2.3.0"
fetch_and_deploy_gh_release "vikunja" "go-vikunja/vikunja" "binary" "${RELEASE}" "" "vikunja-*-$(arch_resolve "x86_64" "aarch64").deb"
msg_info "Setting up Vikunja" msg_info "Setting up Vikunja"
sed -i 's|^# \(service:\)|\1|' /etc/vikunja/config.yml sed -i 's|^# \(service:\)|\1|' /etc/vikunja/config.yml
+12 -16
View File
@@ -922,10 +922,8 @@ choose_and_set_storage_for_file() {
_list_os_versions() { _list_os_versions() {
local ostype="${1:-}" local ostype="${1:-}"
[[ -n "$ostype" ]] || return 0 [[ -n "$ostype" ]] || return 0
local arch
arch="$(dpkg --print-architecture 2>/dev/null || echo amd64)"
pveam available -section system 2>/dev/null | pveam available -section system 2>/dev/null |
grep -E "_${arch}\.(tar\.zst|tar\.xz|tar\.gz)([[:space:]]|$)" | grep -E '\.(tar\.zst|tar\.xz|tar\.gz)$' |
awk '{print $2}' | awk '{print $2}' |
sed -nE "s/^${ostype}-([0-9]+(\.[0-9]+)?).*/\1/p" | sed -nE "s/^${ostype}-([0-9]+(\.[0-9]+)?).*/\1/p" |
sort -u -V || true sort -u -V || true
@@ -938,10 +936,8 @@ _list_os_versions() {
_list_templates() { _list_templates() {
local search="${1:-}" pattern="${2:-}" local search="${1:-}" pattern="${2:-}"
[[ -n "$search" ]] || return 0 [[ -n "$search" ]] || return 0
local arch
arch="$(dpkg --print-architecture 2>/dev/null || echo amd64)"
pveam available -section system 2>/dev/null | pveam available -section system 2>/dev/null |
grep -E "_${arch}\.(tar\.zst|tar\.xz|tar\.gz)([[:space:]]|$)" | grep -E '\.(tar\.zst|tar\.xz|tar\.gz)$' |
awk '{print $2}' | awk '{print $2}' |
grep -E "^${search}.*${pattern}" | grep -E "^${search}.*${pattern}" |
sort -t - -k 2 -V || true sort -t - -k 2 -V || true
@@ -5204,11 +5200,15 @@ EOF
# TSTP = Ctrl+Z, TTIN = bg read from tty, TTOU = bg write to tty (tostop) # TSTP = Ctrl+Z, TTIN = bg read from tty, TTOU = bg write to tty (tostop)
trap '' TSTP TTIN TTOU trap '' TSTP TTIN TTOU
# lxc-attach left us in a background process group - claim the terminal back # lxc-attach takes the controlling terminal while the install runs and does
# before we print anything. Note this does NOT hold: the log collection # not hand it back, leaving us in a background process group. Reading from
# below uses pct pull/exec, which take it away again, so every interactive # the terminal then returns EIO instead of blocking, because SIGTTIN is
# prompt has to reclaim it again right before its read. # ignored above - so every recovery prompt fails before the user can answer.
reclaim_tty # Redirecting to /dev/tty does not help: the rule applies to the terminal,
# not the file descriptor. Claim the foreground group back; SIGTTOU is
# ignored too, so tcsetpgrp() succeeds instead of stopping us. No-op when we
# already are in the foreground. perl is a hard dependency of Proxmox VE.
perl -e 'use POSIX; open(my $t, "+<", "/dev/tty") or exit 1; POSIX::tcsetpgrp(fileno($t), getpgrp()) or exit 1;' 2>/dev/null || true
msg_error "Installation failed in container ${CTID} (exit code: ${install_exit_code})" msg_error "Installation failed in container ${CTID} (exit code: ${install_exit_code})"
@@ -5338,7 +5338,6 @@ EOF
pct enter "$CTID" pct enter "$CTID"
echo "" echo ""
echo -en "${YW}Container ${CTID} still running. Remove now? (y/N): ${CL}" echo -en "${YW}Container ${CTID} still running. Remove now? (y/N): ${CL}"
reclaim_tty
if read -r response </dev/tty && [[ "$response" =~ ^[Yy]$ ]]; then if read -r response </dev/tty && [[ "$response" =~ ^[Yy]$ ]]; then
pct stop "$CTID" &>/dev/null || true pct stop "$CTID" &>/dev/null || true
pct destroy "$CTID" &>/dev/null || true pct destroy "$CTID" &>/dev/null || true
@@ -5498,7 +5497,6 @@ EOF
local response="" local response=""
local read_rc local read_rc
reclaim_tty
read -t 60 -r response </dev/tty read -t 60 -r response </dev/tty
read_rc=$? read_rc=$?
if [[ $read_rc -eq 0 ]]; then if [[ $read_rc -eq 0 ]]; then
@@ -5763,7 +5761,6 @@ destroy_lxc() {
trap 'echo; msg_error "Aborted by user (SIGINT/SIGQUIT)"; return 130' INT QUIT trap 'echo; msg_error "Aborted by user (SIGINT/SIGQUIT)"; return 130' INT QUIT
local prompt local prompt
reclaim_tty
if ! read -rp "Remove this Container? <y/N> " prompt </dev/tty; then if ! read -rp "Remove this Container? <y/N> " prompt </dev/tty; then
# read returns non-zero on Ctrl-D/ESC # read returns non-zero on Ctrl-D/ESC
msg_error "Aborted input (Ctrl-D/ESC)" msg_error "Aborted input (Ctrl-D/ESC)"
@@ -6725,8 +6722,7 @@ create_lxc_container() {
# Step 1: Check local templates first (instant) # Step 1: Check local templates first (instant)
mapfile -t LOCAL_TEMPLATES < <( mapfile -t LOCAL_TEMPLATES < <(
pveam list "$TEMPLATE_STORAGE" 2>/dev/null | pveam list "$TEMPLATE_STORAGE" 2>/dev/null |
awk -v search="${TEMPLATE_SEARCH}" -v pattern="${TEMPLATE_PATTERN}" -v arch="${ARCH}" \ awk -v search="${TEMPLATE_SEARCH}" -v pattern="${TEMPLATE_PATTERN}" '$1 ~ search && $1 ~ pattern {print $1}' |
'$1 ~ search && $1 ~ pattern && $1 ~ ("_" arch "\\.(tar\\.zst|tar\\.xz|tar\\.gz)$") {print $1}' |
sed 's|.*/||' | sort -t - -k 2 -V sed 's|.*/||' | sort -t - -k 2 -V
) )
-33
View File
@@ -1042,39 +1042,6 @@ ensure_tput() {
fi fi
} }
# ------------------------------------------------------------------------------
# reclaim_tty()
#
# - Reclaims the controlling terminal's foreground process group
# - lxc-attach takes the terminal and does not hand it back, leaving us in a
# background process group. Reading from the terminal then returns EIO
# instead of blocking, because SIGTTIN is ignored during recovery - so the
# prompt fails before the user can answer and their keystroke leaks into the
# parent shell. Redirecting to /dev/tty does not help: the rule applies to
# the terminal, not to the file descriptor.
# - pct exec/pull/enter use lxc-attach internally, so the terminal can be taken
# away again at any point. Call this immediately before each interactive
# read, not once after the install.
# - SIGTTOU is ignored inside perl so tcsetpgrp() succeeds instead of stopping
# us. No-op when we already are in the foreground or there is no terminal.
# perl is a hard dependency of Proxmox VE.
# ------------------------------------------------------------------------------
reclaim_tty() {
command -v perl >/dev/null 2>&1 || return 0
[[ -e /dev/tty ]] || return 0
local pgid
pgid=$(ps -o pgid= -p $$ 2>/dev/null | tr -d ' ') || true
perl -e '
use POSIX;
$SIG{TTOU} = "IGNORE";
my $pgid = $ARGV[0] || POSIX::getpgrp();
open(my $t, "+<", "/dev/tty") or exit 1;
POSIX::tcsetpgrp(fileno($t), $pgid) or exit 1;
' "${pgid:-0}" 2>/dev/null || true
}
# ------------------------------------------------------------------------------ # ------------------------------------------------------------------------------
# is_alpine() # is_alpine()
# #
-1
View File
@@ -499,7 +499,6 @@ error_handler() {
local response="" local response=""
local read_rc local read_rc
declare -f reclaim_tty >/dev/null 2>&1 && reclaim_tty
read -t 60 -r response </dev/tty read -t 60 -r response </dev/tty
read_rc=$? read_rc=$?
if [[ $read_rc -eq 0 ]]; then if [[ $read_rc -eq 0 ]]; then
+32 -29
View File
@@ -2576,6 +2576,11 @@ _deploy_unpacked_archive() {
local archive="$1" target="$2" workdir="$3" local archive="$1" target="$2" workdir="$3"
local filename="${archive##*/}" local filename="${archive##*/}"
mkdir -p "$target"
if [[ "${CLEAN_INSTALL:-0}" == "1" ]]; then
find "${target:?}" -mindepth 1 -delete
fi
if [[ "$filename" == *.zip ]]; then if [[ "$filename" == *.zip ]]; then
ensure_dependencies unzip ensure_dependencies unzip
unzip -q "$archive" -d "$workdir" || { unzip -q "$archive" -d "$workdir" || {
@@ -2602,44 +2607,38 @@ _deploy_unpacked_archive() {
return 65 return 65
fi fi
local top_entries inner_dir source_dir local top_entries inner_dir
top_entries=$(find "$workdir" -mindepth 1 -maxdepth 1) top_entries=$(find "$workdir" -mindepth 1 -maxdepth 1)
if [[ "$(echo "$top_entries" | wc -l)" -eq 1 && -d "$top_entries" ]]; then if [[ "$(echo "$top_entries" | wc -l)" -eq 1 && -d "$top_entries" ]]; then
inner_dir="$top_entries" inner_dir="$top_entries"
source_dir="$inner_dir" shopt -s dotglob nullglob
else if compgen -G "$inner_dir/*" >/dev/null; then
source_dir="$workdir" cp -r "$inner_dir"/* "$target/" || {
fi msg_error "Failed to copy contents from $inner_dir to $target"
shopt -u dotglob nullglob
shopt -s dotglob nullglob return 252
if ! compgen -G "$source_dir/*" >/dev/null; then }
if [[ -n "$inner_dir" ]]; then else
msg_error "Inner directory is empty: $inner_dir" msg_error "Inner directory is empty: $inner_dir"
shopt -u dotglob nullglob
return 252
fi
shopt -u dotglob nullglob
else
shopt -s dotglob nullglob
if compgen -G "$workdir/*" >/dev/null; then
cp -r "$workdir"/* "$target/" || {
msg_error "Failed to copy contents to $target"
shopt -u dotglob nullglob
return 252
}
else else
msg_error "Unpacked archive is empty" msg_error "Unpacked archive is empty"
shopt -u dotglob nullglob
return 252
fi fi
shopt -u dotglob nullglob shopt -u dotglob nullglob
return 252
fi fi
# <target> is only touched once the payload is known good. Wiping earlier left
# CLEAN_INSTALL callers with an empty target directory whenever the download
# was truncated, the archive was unreadable, or it unpacked to nothing.
mkdir -p "$target"
if [[ "${CLEAN_INSTALL:-0}" == "1" ]]; then
find "${target:?}" -mindepth 1 -delete
fi
if ! cp -r "$source_dir"/* "$target/"; then
if [[ -n "$inner_dir" ]]; then
msg_error "Failed to copy contents from $inner_dir to $target"
else
msg_error "Failed to copy contents to $target"
fi
shopt -u dotglob nullglob
return 252
fi
shopt -u dotglob nullglob
return 0 return 0
} }
@@ -7733,6 +7732,10 @@ setup_nodejs() {
fi fi
fi fi
if [[ "$(npm -v 2>/dev/null | cut -d. -f1)" -ge 11 ]]; then
$STD npm config set dangerously-allow-all-scripts true --location=global 2>/dev/null || true
fi
# Set a safe default heap limit for Node.js builds if not explicitly provided. # Set a safe default heap limit for Node.js builds if not explicitly provided.
# Priority: # Priority:
# 1) NODE_OPTIONS (caller/user override) # 1) NODE_OPTIONS (caller/user override)
+7 -13
View File
@@ -54,24 +54,18 @@ while true; do
continue continue
fi fi
# Determine type and read the current config directly from Proxmox's pmxcfs. # Determine type and set config command
# Ignore snapshot sections, matching the current config shown by pct/qm config. if pct status $instance >/dev/null 2>&1; then
if [ -r "/etc/pve/lxc/$instance.conf" ]; then
type="ct" type="ct"
config_file="/etc/pve/lxc/$instance.conf" config_cmd="pct config"
else else
type="vm" type="vm"
config_file="/etc/pve/qemu-server/$instance.conf" config_cmd="qm config"
fi fi
config=$(sed '/^\[/,$d' "$config_file")
# Skip templates and onboot-disabled # Skip templates and onboot-disabled
if grep -q "onboot: 0" <<<"$config" || ! grep -q "onboot" <<<"$config"; then onboot=$($config_cmd $instance | grep -q "onboot: 0" || ( ! $config_cmd $instance | grep -q "onboot" ) && echo "true" || echo "false")
onboot="true" template=$($config_cmd $instance | grep -q "^template:" && echo "true" || echo "false")
else
onboot="false"
fi
template=$(grep -q "^template:" <<<"$config" && echo "true" || echo "false")
if [ "$onboot" == "true" ]; then if [ "$onboot" == "true" ]; then
echo "Skipping $instance because it is set not to boot" echo "Skipping $instance because it is set not to boot"
@@ -82,7 +76,7 @@ while true; do
fi fi
# Check for mon-restart tag # Check for mon-restart tag
has_tag=$(grep -q "tags:.*mon-restart" <<<"$config" && echo "true" || echo "false") has_tag=$($config_cmd $instance | grep -q "tags:.*mon-restart" && echo "true" || echo "false")
if [ "$has_tag" != "true" ]; then if [ "$has_tag" != "true" ]; then
echo "Skipping $instance because it does not have 'mon-restart' tag" echo "Skipping $instance because it does not have 'mon-restart' tag"
continue continue
+12
View File
@@ -125,6 +125,12 @@ EOF
no) msg_error "Selected no to Correcting Proxmox VE Sources" ;; no) msg_error "Selected no to Correcting Proxmox VE Sources" ;;
esac esac
if [[ "$(dpkg --print-architecture 2>/dev/null)" == "arm64" ]]; then
msg_ok "ARM64 detected - skipping Proxmox repository setup"
post_routines_common
return
fi
CHOICE=$(whiptail --backtitle "Proxmox VE Helper Scripts" --title "PVE-ENTERPRISE" --menu "The 'pve-enterprise' repository is only available to users who have purchased a Proxmox VE subscription.\n \nDisable 'pve-enterprise' repository?" 14 58 2 \ CHOICE=$(whiptail --backtitle "Proxmox VE Helper Scripts" --title "PVE-ENTERPRISE" --menu "The 'pve-enterprise' repository is only available to users who have purchased a Proxmox VE subscription.\n \nDisable 'pve-enterprise' repository?" 14 58 2 \
"yes" " " \ "yes" " " \
"no" " " 3>&2 2>&1 1>&3) "no" " " 3>&2 2>&1 1>&3)
@@ -282,6 +288,12 @@ EOF
esac esac
fi fi
if [[ "$(dpkg --print-architecture 2>/dev/null)" == "arm64" ]]; then
msg_ok "ARM64 detected - skipping Proxmox repository setup"
post_routines_common
return
fi
# ---- PVE-ENTERPRISE ---- # ---- PVE-ENTERPRISE ----
if component_exists_in_sources "pve-enterprise"; then if component_exists_in_sources "pve-enterprise"; then
CHOICE=$(whiptail --backtitle "Proxmox VE Helper Scripts" \ CHOICE=$(whiptail --backtitle "Proxmox VE Helper Scripts" \
+1 -1
View File
@@ -402,7 +402,7 @@ function advanced_settings() {
fi fi
if CPU_TYPE1=$(whiptail --backtitle "Proxmox VE Helper Scripts" --title "CPU MODEL" --radiolist "Choose CPU Model" --cancel-button Exit-Script 10 58 2 \ if CPU_TYPE1=$(whiptail --backtitle "Proxmox VE Helper Scripts" --title "CPU MODEL" --radiolist "Choose CPU Model" --cancel-button Exit-Script 10 58 2 \
"KVM64" "Default - safe for migration/compatibility" ON \ "KVM64" "Default safe for migration/compatibility" ON \
"Host" "Use host CPU features (faster, no migration)" OFF \ "Host" "Use host CPU features (faster, no migration)" OFF \
3>&1 1>&2 2>&3); then 3>&1 1>&2 2>&3); then
case "$CPU_TYPE1" in case "$CPU_TYPE1" in