fix: Add nginx cleanup to all build scripts

- Add nginx config cleanup to build-image.sh and build-rpi-usb.sh
- Moves location-only configs from conf.d/sites-enabled to secubox.d/
- Tests nginx configuration after package install
- Matches existing cleanup in build-live-usb.sh

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
CyberMind-FR 2026-04-08 08:08:45 +02:00
parent 74ec25436b
commit 16cf0eb529
2 changed files with 91 additions and 0 deletions

View File

@ -362,6 +362,52 @@ if [[ $SLIPSTREAM_DEBS -eq 1 ]]; then
# Nettoyer
rm -rf "${ROOTFS}/tmp/secubox-debs"
ok "Slipstream: ${INSTALLED_COUNT}/${SLIP_COUNT} paquets installés"
# ── Nginx cleanup after package install ──────────────────────────────────
log "Cleaning bad nginx configs from conf.d..."
for conf in "${ROOTFS}/etc/nginx/conf.d/"*secubox*.conf "${ROOTFS}/etc/nginx/conf.d/secubox-"*; do
[[ -f "$conf" ]] || [[ -L "$conf" ]] || continue
real_file="$conf"
if [[ -L "$conf" ]]; then
target=$(readlink "$conf")
if [[ "$target" == /* ]]; then
real_file="${ROOTFS}${target}"
else
real_file="${ROOTFS}/etc/nginx/conf.d/${target}"
fi
fi
if [[ -f "$real_file" ]] && grep -q "^location" "$real_file" 2>/dev/null; then
base=$(basename "$conf" .conf | sed 's/^secubox-//')
mkdir -p "${ROOTFS}/etc/nginx/secubox.d"
if [[ ! -f "${ROOTFS}/etc/nginx/secubox.d/${base}.conf" ]]; then
cp "$real_file" "${ROOTFS}/etc/nginx/secubox.d/${base}.conf" 2>/dev/null || true
fi
rm -f "$conf"
fi
done
log "Cleaning bad nginx configs from sites-enabled..."
for site in "${ROOTFS}/etc/nginx/sites-enabled/"*; do
[[ -f "$site" ]] || [[ -L "$site" ]] || continue
[[ "$(basename "$site")" == "secubox" ]] && continue
real_file="$site"
[[ -L "$site" ]] && real_file=$(readlink -f "$site") && real_file="${ROOTFS}${real_file#${ROOTFS}}"
[[ -f "$real_file" ]] || { rm -f "$site"; continue; }
if grep -q "^location" "$real_file" 2>/dev/null && ! grep -q "^server" "$real_file" 2>/dev/null; then
base=$(basename "$site" | sed 's/^secubox-//')
mkdir -p "${ROOTFS}/etc/nginx/secubox.d"
cp "$real_file" "${ROOTFS}/etc/nginx/secubox.d/${base}.conf" 2>/dev/null || true
rm -f "$site"
fi
done
# Test nginx configuration
if chroot "${ROOTFS}" nginx -t 2>&1; then
ok "Nginx configuration valid"
else
warn "Nginx configuration has errors (will be fixed at firstboot)"
fi
else
warn "Slipstream: pas de secubox-*.deb dans output/ ou output/debs/"
fi

View File

@ -707,6 +707,51 @@ fi
rm -rf "${ROOTFS}/tmp/secubox-debs"
# ── Nginx cleanup after package install ──────────────────────────────────
log "Cleaning bad nginx configs from conf.d..."
for conf in "${ROOTFS}/etc/nginx/conf.d/"*secubox*.conf "${ROOTFS}/etc/nginx/conf.d/secubox-"*; do
[[ -f "$conf" ]] || [[ -L "$conf" ]] || continue
real_file="$conf"
if [[ -L "$conf" ]]; then
target=$(readlink "$conf")
if [[ "$target" == /* ]]; then
real_file="${ROOTFS}${target}"
else
real_file="${ROOTFS}/etc/nginx/conf.d/${target}"
fi
fi
if [[ -f "$real_file" ]] && grep -q "^location" "$real_file" 2>/dev/null; then
base=$(basename "$conf" .conf | sed 's/^secubox-//')
mkdir -p "${ROOTFS}/etc/nginx/secubox.d"
if [[ ! -f "${ROOTFS}/etc/nginx/secubox.d/${base}.conf" ]]; then
cp "$real_file" "${ROOTFS}/etc/nginx/secubox.d/${base}.conf" 2>/dev/null || true
fi
rm -f "$conf"
fi
done
log "Cleaning bad nginx configs from sites-enabled..."
for site in "${ROOTFS}/etc/nginx/sites-enabled/"*; do
[[ -f "$site" ]] || [[ -L "$site" ]] || continue
[[ "$(basename "$site")" == "secubox" ]] && continue
real_file="$site"
[[ -L "$site" ]] && real_file=$(readlink -f "$site") && real_file="${ROOTFS}${real_file#${ROOTFS}}"
[[ -f "$real_file" ]] || { rm -f "$site"; continue; }
if grep -q "^location" "$real_file" 2>/dev/null && ! grep -q "^server" "$real_file" 2>/dev/null; then
base=$(basename "$site" | sed 's/^secubox-//')
mkdir -p "${ROOTFS}/etc/nginx/secubox.d"
cp "$real_file" "${ROOTFS}/etc/nginx/secubox.d/${base}.conf" 2>/dev/null || true
rm -f "$site"
fi
done
# Test nginx configuration
if chroot "${ROOTFS}" nginx -t 2>&1; then
ok "Nginx configuration valid"
else
warn "Nginx configuration has errors (will be fixed at firstboot)"
fi
# Clean apt cache (keep lists for potential future use)
chroot "${ROOTFS}" apt-get clean