Files
2026-08-18 22:51:35 +08:00

183 lines
8.7 KiB
Bash
Executable File
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
#!/usr/bin/env bash
set -Eeuo pipefail
umask 027
LOG_LOCALE=${KAIDI_LOG_LOCALE:-zh-CN}
localize_message() {
local message=$1
[ "$LOG_LOCALE" = en ] && { printf '%s' "$message"; return; }
case "$message" in
"Configuration file is not a regular file: "*) printf '配置文件不是普通文件:%s' "${message#Configuration file is not a regular file: }" ;;
"Startup user cannot read configuration file: "*) printf '启动用户无法读取配置文件:%s' "${message#Startup user cannot read configuration file: }" ;;
"Configuration file is too large: "*) printf '配置文件过大:%s' "${message#Configuration file is too large: }" ;;
"Configuration file contains an invalid line: "*) printf '配置文件包含无效行:%s' "${message#Configuration file contains an invalid line: }" ;;
"app.jar is missing from "*) printf '缺少 app.jar:%s' "${message#app.jar is missing from }" ;;
"public/index.html is missing from "*) printf '缺少前端入口 public/index.html:%s' "${message#public/index.html is missing from }" ;;
"VERSION is missing from "*) printf '缺少 VERSION:%s' "${message#VERSION is missing from }" ;;
"Java 17 or newer was not found") printf '未找到 Java 17 或更高版本' ;;
"Java executable is not available at "*) printf 'Java 可执行文件不可用:%s' "${message#Java executable is not available at }" ;;
"Java executable "*" is not available") printf 'Java 可执行文件不可用' ;;
"Java 17 or newer is required") printf '需要 Java 17 或更高版本' ;;
*" is missing from the protected Kaidi configuration") printf '受保护的 Kaidi 配置缺少:%s' "${message% is missing from the protected Kaidi configuration}" ;;
"Storage directory "*" does not exist") printf '存储目录不存在:%s' "${message#Storage directory }" ;;
"Startup user cannot write storage directory "*) printf '启动用户无法写入存储目录:%s' "${message#Startup user cannot write storage directory }" ;;
"PID directory does not exist") printf 'PID 目录不存在' ;;
"Startup user cannot write the PID directory") printf '启动用户无法写入 PID 目录' ;;
"KAIDI_PID_FILE must be an absolute path") printf 'KAIDI_PID_FILE 必须是绝对路径' ;;
"PID file must not be a symbolic link") printf 'PID 文件不能是符号链接' ;;
"Process start time could not be read"*) printf '无法读取进程启动时间' ;;
*) printf '%s' "$message" ;;
esac
}
die() {
printf '[kaidi-baota] 错误:%s\n' "$(localize_message "$1")" >&2
exit 1
}
SCRIPT_DIR=$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)
RELEASE_ROOT=$(cd "$SCRIPT_DIR/.." && pwd -P)
APP_JAR="$RELEASE_ROOT/app.jar"
PUBLIC_INDEX="$RELEASE_ROOT/public/index.html"
VERSION_FILE="$RELEASE_ROOT/VERSION"
CONFIG_FILE=${KAIDI_CONFIG_FILE:-/etc/kaidi/kaidi.env}
RUNTIME_ENV_FILE=${KAIDI_RUNTIME_ENV_FILE:-/var/lib/kaidi/setup/application.env}
decode_env_value() {
local raw=$1 result='' char next index=0 length
if [[ "$raw" == \"*\" && ${#raw} -ge 2 ]]; then
raw=${raw:1:${#raw}-2}
length=${#raw}
while [ "$index" -lt "$length" ]; do
char=${raw:index:1}
if [ "$char" = "\\" ] && [ $((index + 1)) -lt "$length" ]; then
next=${raw:index+1:1}
if [ "$next" = "\\" ] || [ "$next" = '"' ]; then
result+="$next"
index=$((index + 2))
continue
fi
fi
result+="$char"
index=$((index + 1))
done
printf '%s' "$result"
elif [[ "$raw" == \'*\' && ${#raw} -ge 2 ]]; then
printf '%s' "${raw:1:${#raw}-2}"
else
printf '%s' "$raw"
fi
}
is_managed_env_name() {
case "$1" in
SPRING_PROFILES_ACTIVE|SERVER_ADDRESS|SERVER_PORT|SESSION_COOKIE_SECURE|\
DB_URL|DB_USERNAME|DB_PASSWORD|FIELD_ENCRYPTION_KEY|\
FILE_STORAGE_ROOT|FILE_STORAGE_TEMP|FILE_SCANNER_ENABLED|FILE_SCANNER_HOST|FILE_SCANNER_PORT|\
FINANCE_BOOTSTRAP_ENABLED|FINANCE_BOOTSTRAP_PASSWORD|FINANCE_SETUP_ENABLED|\
FINANCE_SETUP_TOKEN_SHA256|FINANCE_SETUP_ENV_FILE|FINANCE_SETUP_MARKER_FILE|\
FINANCE_SETUP_RESTART_AFTER_COMPLETE|FINANCE_UPDATE_ENABLED|\
UPDATE_RELEASE_BASE_URL|UPDATE_RELEASE_API_URL|UPDATE_RELEASE_TOKEN|\
UPDATE_REQUEST_FILE|UPDATE_STATUS_FILE|UPDATE_CURRENT_VERSION_FILE|APP_VERSION|KAIDI_PID_FILE|KAIDI_JAVA_BIN)
return 0
;;
*) return 1 ;;
esac
}
load_env_file() {
local file=$1 line name raw value size
[ -e "$file" ] || return 0
[ -f "$file" ] && [ ! -L "$file" ] || die "Configuration file is not a regular file: $file"
[ -r "$file" ] || die "Startup user cannot read configuration file: $file"
size=$(wc -c < "$file" | tr -d '[:space:]')
[ "$size" -le 65536 ] || die "Configuration file is too large: $file"
while IFS= read -r line || [ -n "$line" ]; do
case "$line" in ''|'#'*) continue ;; esac
[[ "$line" =~ ^([A-Za-z_][A-Za-z0-9_]*)=(.*)$ ]] \
|| die "Configuration file contains an invalid line: $file"
name=${BASH_REMATCH[1]}
raw=${BASH_REMATCH[2]}
is_managed_env_name "$name" || continue
[ -n "${!name:-}" ] && continue
value=$(decode_env_value "$raw")
printf -v "$name" '%s' "$value"
export "${name?}"
done < "$file"
}
[ -s "$APP_JAR" ] || die "app.jar is missing from $RELEASE_ROOT"
[ -s "$PUBLIC_INDEX" ] || die "public/index.html is missing from $RELEASE_ROOT"
[ -s "$VERSION_FILE" ] || die "VERSION is missing from $RELEASE_ROOT"
# The setup-generated runtime file has precedence over the base file. Non-empty
# variables supplied by Baota have precedence over both; empty panel fields do not
# mask the protected configuration written by the setup wizard. The systemd unit
# loads both files itself as root, then sets KAIDI_ENV_PRELOADED so the service
# user never needs traversal permission for /etc/kaidi (which is intentionally
# root-only).
if [ "${KAIDI_ENV_PRELOADED:-false}" != true ]; then
load_env_file "$RUNTIME_ENV_FILE"
load_env_file "$CONFIG_FILE"
fi
JAVA_BIN=${KAIDI_JAVA_BIN:-}
if [ -z "$JAVA_BIN" ] && [ -n "${JAVA_HOME:-}" ]; then
JAVA_BIN="$JAVA_HOME/bin/java"
fi
if [ -z "$JAVA_BIN" ] && [ -x /opt/kaidi/runtime/java/bin/java ]; then
# Compatibility for installations created before external Java paths were persisted.
JAVA_BIN=/opt/kaidi/runtime/java/bin/java
fi
if [ -z "$JAVA_BIN" ]; then
JAVA_BIN=$(command -v java 2>/dev/null || true)
fi
[ -n "$JAVA_BIN" ] || die "Java 17 or newer was not found"
if [[ "$JAVA_BIN" == */* ]]; then
[ -x "$JAVA_BIN" ] || die "Java executable is not available at $JAVA_BIN"
else
command -v "$JAVA_BIN" >/dev/null 2>&1 || die "Java executable $JAVA_BIN is not available"
fi
JAVA_VERSION=$("$JAVA_BIN" -version 2>&1 | sed -n 's/.*version "\([0-9][0-9]*\).*/\1/p' | head -n 1)
[[ "$JAVA_VERSION" =~ ^[0-9]+$ ]] && [ "$JAVA_VERSION" -ge 17 ] \
|| die "Java 17 or newer is required"
export SPRING_PROFILES_ACTIVE=${SPRING_PROFILES_ACTIVE:-production}
export SERVER_ADDRESS=${SERVER_ADDRESS:-127.0.0.1}
export SERVER_PORT=${SERVER_PORT:-18080}
export FINANCE_SETUP_ENABLED=${FINANCE_SETUP_ENABLED:-false}
export FINANCE_BOOTSTRAP_ENABLED=${FINANCE_BOOTSTRAP_ENABLED:-false}
export FINANCE_UPDATE_ENABLED=${FINANCE_UPDATE_ENABLED:-true}
export FILE_SCANNER_ENABLED=${FILE_SCANNER_ENABLED:-false}
export FINANCE_STATIC_LOCATIONS=${FINANCE_STATIC_LOCATIONS:-file:$RELEASE_ROOT/public/}
export UPDATE_CURRENT_VERSION_FILE=${UPDATE_CURRENT_VERSION_FILE:-$VERSION_FILE}
export APP_VERSION=${APP_VERSION:-$(tr -d '\r\n' < "$VERSION_FILE")}
export KAIDI_PID_FILE=${KAIDI_PID_FILE:-/var/lib/kaidi/kaidi.pid}
if [ "$FINANCE_SETUP_ENABLED" != true ]; then
for name in DB_URL DB_USERNAME DB_PASSWORD FIELD_ENCRYPTION_KEY FILE_STORAGE_ROOT FILE_STORAGE_TEMP; do
[ -n "${!name:-}" ] || die "$name is missing from the protected Kaidi configuration"
done
for directory in "$FILE_STORAGE_ROOT" "$FILE_STORAGE_TEMP"; do
[ -d "$directory" ] || die "Storage directory $directory does not exist"
[ -w "$directory" ] || die "Startup user cannot write storage directory $directory"
done
fi
case "$KAIDI_PID_FILE" in /*) ;; *) die "KAIDI_PID_FILE must be an absolute path" ;; esac
[ -d "$(dirname "$KAIDI_PID_FILE")" ] || die "PID directory does not exist"
[ -w "$(dirname "$KAIDI_PID_FILE")" ] || die "Startup user cannot write the PID directory"
[ ! -L "$KAIDI_PID_FILE" ] || die "PID file must not be a symbolic link"
PID_START_TIME=$(awk '{print $22}' "/proc/$$/stat" 2>/dev/null || true)
[[ "$PID_START_TIME" =~ ^[0-9]+$ ]] || die "Process start time could not be read from /proc"
PID_TEMP="${KAIDI_PID_FILE}.next.$$"
printf '%s %s\n' "$$" "$PID_START_TIME" > "$PID_TEMP"
chmod 0640 "$PID_TEMP"
mv -f "$PID_TEMP" "$KAIDI_PID_FILE"
cd "$RELEASE_ROOT"
exec "$JAVA_BIN" -XX:MaxRAMPercentage=70 -Dfile.encoding=UTF-8 \
"-Dkaidi.release.path=$RELEASE_ROOT" "-Dkaidi.release.version=$APP_VERSION" \
-jar "$APP_JAR"