fix: block unsafe sudo auto install and prevent doctor from rewriting env

This commit is contained in:
wnlen
2026-04-29 17:58:53 +08:00
parent fae7a75f7d
commit 30f78ebb17
2 changed files with 34 additions and 6 deletions
+2
View File
@@ -12,7 +12,9 @@ source "$PROJECT_DIR/scripts/init/systemd-user.sh"
source "$PROJECT_DIR/scripts/init/script.sh" source "$PROJECT_DIR/scripts/init/script.sh"
init_project_context "$PROJECT_DIR" init_project_context "$PROJECT_DIR"
guard_unsafe_sudo_auto_install "${1:-}"
load_env_if_exists load_env_if_exists
migrate_env_legacy_compat_fields "$PROJECT_DIR/.env"
detect_install_scope "${1:-auto}" detect_install_scope "${1:-auto}"
ensure_project_not_wsl_windows_mount ensure_project_not_wsl_windows_mount
+32 -6
View File
@@ -288,9 +288,6 @@ ensure_project_not_wsl_windows_mount() {
} }
load_env_if_exists() { load_env_if_exists() {
local env_file
env_file="$PROJECT_DIR/.env"
if [ -f "$PROJECT_DIR/.env" ]; then if [ -f "$PROJECT_DIR/.env" ]; then
set -a set -a
# shellcheck disable=SC1090 # shellcheck disable=SC1090
@@ -299,7 +296,6 @@ load_env_if_exists() {
fi fi
normalize_env_compat normalize_env_compat
cleanup_env_legacy_compat_fields "$env_file"
} }
normalize_env_compat() { normalize_env_compat() {
@@ -346,12 +342,15 @@ normalize_env_compat() {
return 0 return 0
} }
cleanup_env_legacy_compat_fields() { migrate_env_legacy_compat_fields() {
local file="$1" local file="$1"
local tmp
[ -n "${file:-}" ] || return 0 [ -n "${file:-}" ] || return 0
[ -f "$file" ] || return 0 [ -f "$file" ] || return 0
tmp="$(mktemp "${file}.tmp.XXXXXX")" || return 0
awk ' awk '
$0 ~ /^[[:space:]]*(export[[:space:]]+)?BUILD_MIN_SUCCESS_SOURCES=/ { next } $0 ~ /^[[:space:]]*(export[[:space:]]+)?BUILD_MIN_SUCCESS_SOURCES=/ { next }
$0 ~ /^[[:space:]]*(export[[:space:]]+)?CLASH_SUBSCRIPTION_FORMAT=/ { next } $0 ~ /^[[:space:]]*(export[[:space:]]+)?CLASH_SUBSCRIPTION_FORMAT=/ { next }
@@ -360,7 +359,23 @@ cleanup_env_legacy_compat_fields() {
next next
} }
{ print } { print }
' "$file" > "${file}.tmp" && mv "${file}.tmp" "$file" ' "$file" > "$tmp" || {
rm -f "$tmp" 2>/dev/null || true
return 0
}
if cmp -s "$file" "$tmp"; then
rm -f "$tmp" 2>/dev/null || true
return 0
fi
if [ ! -w "$file" ]; then
rm -f "$tmp" 2>/dev/null || true
warn ".env 当前用户不可写,已跳过兼容迁移:$file"
return 0
fi
mv -f "$tmp" "$file"
} }
github_proxy_prefix() { github_proxy_prefix() {
@@ -1116,6 +1131,17 @@ ensure_openwrt_install_supported() {
fi fi
} }
guard_unsafe_sudo_auto_install() {
local requested="${1:-}"
if [ "$(id -u)" -eq 0 ] \
&& [ -n "${SUDO_USER:-}" ] \
&& { [ -z "${requested:-}" ] || [ "$requested" = "auto" ]; }; then
die_state "检测到未受支持的安装方式:sudo bash install.sh" \
"普通安装请执行:bash install.sh;系统级安装请显式执行:sudo bash install.sh system"
fi
}
detect_install_scope() { detect_install_scope() {
local requested="${1:-auto}" local requested="${1:-auto}"