fix(deploy): 安装脚本的 apt 调用抑制 needrestart 以免重跑时重启代理,服务单元与镜像列表先读完再匹配避免 pipefail 下的 SIGPIPE 误判

This commit is contained in:
Lemon-miaow committed 2026-09-25 11:49:39 +08:00
1 parent 9a5225f77e
commit 367ef2678a
2 files changed
+88 -3

No files matched your search

+22 -3
View File
@@ -690,9 +690,14 @@ wait_for_pkg_locks() {
done
}
# NEEDRESTART_SUSPEND keeps Ubuntu's needrestart hook from restarting services after
# the install's own apt runs. It would restart felis-velocity whenever a rerun
# happens to install or upgrade a package (the running JVM maps files the rerun
# replaces), dropping every player on a rerun that changed nothing the proxy runs.
# The installer restarts what it changes itself.
apt_get() {
wait_for_pkg_locks
DEBIAN_FRONTEND=noninteractive apt-get \
NEEDRESTART_SUSPEND=1 DEBIAN_FRONTEND=noninteractive apt-get \
-o DPkg::Lock::Timeout="$PKG_LOCK_TIMEOUT" \
"$@"
}
@@ -1265,7 +1270,10 @@ EOF
# digest ref the Deployment names and kubelet finds it. A docker save/import round
# trip rewrites the manifest and would leave a copy the digest ref never matches.
import_registry_image() {
if k3s_cmd ctr images ls -q 2>/dev/null | grep -qxF "$(registry_image_containerd_ref)"; then
local images
# Read the list whole before matching; see postgres_installed for the SIGPIPE.
images="$(k3s_cmd ctr images ls -q 2>/dev/null || true)"
if grep -qxF "$(registry_image_containerd_ref)" <<<"$images"; then
ok "registry image ${REGISTRY_IMAGE} already in k3s containerd"
return 0
fi
@@ -2642,8 +2650,19 @@ init_postgres_data_dir() {
fi
}
# postgres_installed reports whether a PostgreSQL client and server unit are present.
# The unit list is read into a variable before matching: `systemctl list-unit-files |
# grep -q` dies of SIGPIPE under pipefail once grep stops reading a list longer than
# one write, and the install then took the "not installed" branch on a host that has it.
postgres_installed() {
local units
command -v psql >/dev/null 2>&1 || return 1
units="$(systemctl list-unit-files 2>/dev/null)" || return 1
grep -q '^postgresql' <<<"$units"
}
install_postgres() {
if command -v psql >/dev/null 2>&1 && systemctl list-unit-files 2>/dev/null | grep -q '^postgresql'; then
if postgres_installed; then
ok "postgresql already installed"
else
log "installing postgresql"
+66
View File
@@ -2072,6 +2072,72 @@ case "$out" in *WARN:*) echo "FAIL: a first install must not restore the binary
rm -rf "$hbdir"
# --- a rerun reads the host right and keeps the proxy up --------------------------------
# Both checks run under bootstrap.sh's own `set -Eeuo pipefail`. The lists are far past one
# pipe buffer with the match on the first line, so a `cmd | grep -q` has grep exit while cmd
# is still writing: cmd dies of SIGPIPE, pipefail fails the pipeline, and the install took
# the "missing" branch on a host that had it (CI caught the PostgreSQL case reinstalling a
# package on a rerun). apt then ran needrestart, which restarted felis-velocity.
for f in postgres_installed import_registry_image apt_get; do
[ -n "$(awk '/^'"$f"'\(\) \{/,/^}/' "$BS")" ] || { echo "FAIL: no ${f} in $BS"; exit 1; }
[ "$(awk '/^'"$f"'\(\) \{/,/^}/' "$BS" | wc -l)" -lt 20 ] \
|| { echo "FAIL: the extracted ${f} is not just the function -- did its closing brace move?"; exit 1; }
done
rrdir="$(mktemp -d)"
printf '#!/bin/sh\nexit 0\n' > "$rrdir/psql"
cat > "$rrdir/systemctl" <<'EOF'
#!/bin/sh
printf '%s\n' "$FIRST_UNIT"
seq 1 200000 | sed 's/.*/unit-&.service static -/'
EOF
cat > "$rrdir/apt-get" <<'EOF'
#!/bin/sh
echo "NEEDRESTART_SUSPEND=${NEEDRESTART_SUSPEND:-unset} $*"
EOF
chmod +x "$rrdir/psql" "$rrdir/systemctl" "$rrdir/apt-get"
run_pg() { # first unit line
PATH="$rrdir:$PATH" FIRST_UNIT="$1" bash -c '
set -Eeuo pipefail
'"$(awk '/^postgres_installed\(\) \{/,/^}/' "$BS")"'
if postgres_installed; then echo INSTALLED; else echo MISSING; fi'
}
expect "an installed PostgreSQL is found in a long unit list" "INSTALLED" "$(run_pg 'postgresql.service enabled enabled')"
expect "a host without the unit still gets PostgreSQL installed" "MISSING" "$(run_pg 'nginx.service enabled enabled')"
run_reg() {
bash -c '
set -Eeuo pipefail
ok() { echo "OK: $*"; }; log() { echo "LOG: $*"; }; warn() { echo "WARN: $*"; }
REGISTRY_IMAGE=registry:2
registry_image_containerd_ref() { echo docker.io/library/registry:2; }
k3s_cmd() {
if [ "$1" = ctr ]; then
echo docker.io/library/registry:2
seq 1 200000 | sed "s/.*/example.test\/img-&:1/"
else
echo "PULLED $*"
fi
}
'"$(awk '/^import_registry_image\(\) \{/,/^}/' "$BS")"'
import_registry_image'
}
out="$(run_reg)"
expect "an imported registry image is found in a long image list" "OK: registry image registry:2 already in k3s containerd" "$out"
case "$out" in *PULLED*) echo "FAIL: the registry image was pulled again"; fails=$((fails + 1)) ;; esac
out="$(PATH="$rrdir:$PATH" bash -c '
set -Eeuo pipefail
wait_for_pkg_locks() { :; }
PKG_LOCK_TIMEOUT=5
'"$(awk '/^apt_get\(\) \{/,/^}/' "$BS")"'
apt_get install -y postgresql')"
expect "the install's apt runs keep needrestart from restarting services" \
"NEEDRESTART_SUSPEND=1 -o DPkg::Lock::Timeout=5 install -y postgresql" "$out"
rm -rf "$rrdir"
# ---------------------------------------------------------------------------------------
if [ "$fails" -eq 0 ]; then
echo "ALL PASS"