From 4d6a9307e5779b88a7722953e03931a046ad105f Mon Sep 17 00:00:00 2001 From: Qiufeng Date: Tue, 4 Aug 2026 10:03:18 +0800 Subject: [PATCH] fix: support legacy systemd path parsing --- install.sh | 10 +++++++--- tests/release-scripts.test.sh | 10 ++++++++++ 2 files changed, 17 insertions(+), 3 deletions(-) diff --git a/install.sh b/install.sh index c9b03b8..4581464 100755 --- a/install.sh +++ b/install.sh @@ -442,8 +442,8 @@ User=$ERP_USER Group=$ERP_GROUP Environment="ERP_INSTALL_ROOT=$INSTALL_ROOT" Environment="ERP_CONFIG_FILE=$CONFIG_FILE" -WorkingDirectory="$INSTALL_ROOT" -ExecStart="$INSTALL_ROOT/current/bin/erp-run" +WorkingDirectory=$INSTALL_ROOT +ExecStart=$INSTALL_ROOT/current/bin/erp-run Restart=always RestartSec=3 TimeoutStopSec=90 @@ -453,12 +453,16 @@ NoNewPrivileges=true PrivateTmp=true ProtectSystem=full ProtectHome=true -ReadWritePaths="$INSTALL_ROOT" "$CONFIG_ROOT" "$STATE_ROOT" "$LOG_ROOT" +ReadWritePaths=$INSTALL_ROOT $CONFIG_ROOT $STATE_ROOT $LOG_ROOT [Install] WantedBy=multi-user.target EOF systemctl daemon-reload + if command -v systemd-analyze >/dev/null 2>&1; then + systemd-analyze verify /etc/systemd/system/kaidi-erp.service \ + || fail 'generated systemd unit is invalid; run systemd-analyze verify /etc/systemd/system/kaidi-erp.service' + fi systemctl enable kaidi-erp.service systemctl restart kaidi-erp.service else diff --git a/tests/release-scripts.test.sh b/tests/release-scripts.test.sh index f0c239a..a66e3c6 100755 --- a/tests/release-scripts.test.sh +++ b/tests/release-scripts.test.sh @@ -474,6 +474,15 @@ test_systemd_unit_uses_compatible_protection() ( ! grep -Fq 'ProtectSystem=strict' "$PROJECT_ROOT/install.sh" ) +test_systemd_unit_uses_unquoted_legacy_paths() ( + local unit + unit="$(sed -n '/^ cat > \/etc\/systemd\/system\/kaidi-erp.service/,/^ systemctl daemon-reload/p' "$PROJECT_ROOT/install.sh")" + grep -Fqx 'WorkingDirectory=$INSTALL_ROOT' <<< "$unit" + grep -Fqx 'ExecStart=$INSTALL_ROOT/current/bin/erp-run' <<< "$unit" + grep -Fqx 'ReadWritePaths=$INSTALL_ROOT $CONFIG_ROOT $STATE_ROOT $LOG_ROOT' <<< "$unit" + ! grep -Fq 'WorkingDirectory="$INSTALL_ROOT"' <<< "$unit" +) + test_no_service_install_disables_online_update() ( local tmp tmp="$(mktemp -d "${TMPDIR:-/tmp}/erp-no-service-test.XXXXXX")" || return 1 @@ -526,6 +535,7 @@ run_test 'installer moves database setup to the web wizard' test_installer_moves run_test 'installer requires an explicit Gitea URL' test_installer_requires_explicit_gitea_url run_test 'Linux production install requires systemd' test_linux_service_preflight_requires_systemd run_test 'systemd unit uses compatible protection' test_systemd_unit_uses_compatible_protection +run_test 'systemd unit uses unquoted legacy paths' test_systemd_unit_uses_unquoted_legacy_paths run_test 'no-service install disables online update' test_no_service_install_disables_online_update run_test 'release workflow uses the scoped Gitea job token' test_release_workflow_uses_scoped_job_token run_test 'installer starts correctly when piped to bash' test_installer_runs_when_piped_to_bash