Repository navigation
Tags: codetot-web/runcloud-bash-scripts
Tags
remove ClamAV/rootkit deep scan from wp-security-audit.sh The ClamAV + rkhunter + chkrootkit deep scan caused high CPU load on production servers (sg3, litesoup work item #4). The audit now runs fast pattern detection only — no extra packages needed. Changes: - Removed --install-deps flag and dependency install block - Removed ClamAV/rkhunter/chkrootkit availability checks - Removed Phase 2 deep scan section entirely - Updated wp-security-audit-installer.sh (no longer installs clamav/rkhunter/chkrootkit) - Updated README and CHANGELOG
fix(wp-migration): parse table_prefix correctly, not as ';' (closes #25… …) (#26) The previous parser used `sed "s/.*'//; s/'.*//"` which is greedy: for a normal line `$table_prefix = 'wp_';`, the first sed matches up to and including the closing single-quote, leaving just `;`. This broke step 6 silently — the URL-update query became `SELECT ... FROM ;options`, mysql errored out under suppressed stderr, and the staging URL never applied to the destination database. Switch to `awk -F"'" '/^\$table_prefix[[:space:]]*=/ {print $2; exit}'` which is robust against whitespace variants and unaffected by the greedy-matching pitfall. Add empty-check and `[A-Za-z0-9_]+` validation since the prefix is interpolated unquoted into SQL during step 6. Bumps VERSION to 0.0.1.3. Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
fix(wp-migration): SSH multiplexing + fail loudly on DB import error (c… …loses #23) (#24) Two UX/correctness fixes for wp-migration.sh: 1. SSH connection multiplexing The script runs ~8 separate ssh/rsync invocations. With password auth the user was prompted every single time. Add ControlMaster=auto + ControlPath in a per-run mktemp dir + ControlPersist=10m so the first connection opens a control socket and subsequent calls reuse it. Trap on EXIT cleans up the socket dir. 2. Database import error masking The mysql import was piped through `grep -v ... || true`, which masked real failures: an `ERROR 1045 Access denied` would print to the screen and the very next line would still claim "Database imported successfully". Switch to `bash -s` heredoc so process substitution `2> >(grep -v ...)` filters only deprecation warnings without touching mysql's exit code, capture status, exit with it. Local side gates the success message behind `if !` and prints an actionable hint about destination DB/user/password requirements. Bumps VERSION to 0.0.1.2. Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
fix(wp-migration): auto-detect source user instead of using $USER (cl… …oses #21) (#22) The source path was built from $USER which evaluates to "root" when the script is invoked as root, producing /home/root/webapps/<app> — a path that never exists. Hardcoding "runcloud" would also miss private servers that use custom system users. Now scans /home/*/webapps/<appname> to auto-detect the owning user. If the glob returns exactly one match it's used; multiple or no matches error out with an actionable message. SRC_USER=<user> env var still overrides for edge cases. Bumps VERSION to 0.0.1.1 and finalizes the [Unreleased] CHANGELOG section into a [0.0.1.1] release alongside the wp-git-cleanup index.lock fix. Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>