Compare commits

..

No commits in common. "main" and "0.1.1" have entirely different histories.
main ... 0.1.1

3 changed files with 47 additions and 78 deletions

View file

@ -12,18 +12,6 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
### Removed
## [0.2.0] - 2022-04-22
### Added
- Test condition when there are no errors
- Log unjoinable instances
- A message when instance can be accessed
### Fixed
- Silence curl's output
## [0.1.1] - 2021-08-29
### Added

View file

@ -44,11 +44,11 @@ and date of expired certificate, default: `1210000`, 2w
- `INSTANCE_LAST_CHANCE_TIMEOUT`, integer, timeout in seconds to connect to an
instance that was previously not accessible, default: `30`
- `MEDIA_REMOVE_DAYS`, integer, how old in days media attachments have to be
before getting removed, default: `7`
before getting removed
- `CARDS_REMOVE_DAYS`, integer, how old in days cards previews have to be
before getting removed, default: `15`
before getting removed
- `STATUSES_REMOVE_DAYS`, integer, how old in days unreferenced statuses have
to be before getting removed, default: `30`
to be before getting removed
Example:

View file

@ -40,68 +40,52 @@ accounts_cull() {
# Remove instances that have an expired certificate from more than
# TLS_EXPIRED_MAX_SEC
if grep -q 'certificate has expired' "$CULL_LOG"; then
grep 'certificate has expired' "$CULL_LOG" \
| awk '{print $NF}' \
| cut -d'/' -f3 \
| sort -u \
> "$TLS_EXPIRED_LOG"
grep 'certificate has expired' "$CULL_LOG" \
| awk '{print $NF}' \
| cut -d'/' -f3 \
| sort -u \
> "$TLS_EXPIRED_LOG"
while read -r instance; do
TLS_EXPIRED_TS=$(
date -d "$(
echo Q \
| openssl s_client \
-servername "$instance" \
-connect "${instance}":443 \
2>/dev/null \
| openssl x509 -noout -dates \
| grep 'notAfter' \
| cut -d'=' -f2
)" +%s
)
DATE_DIFF=$(($(date +%s) - TLS_EXPIRED_TS))
if [[ $DATE_DIFF -gt $TLS_EXPIRED_MAX_SEC ]]; then
echo "${instance} has a certificate expired for more than TLS_EXPIRED_MAX_SEC, purging..."
$DRY_RUN \
&& $TOOTCTL domains purge \
--concurrency "$DB_POOL" \
--dry-run \
"$instance"
$DRY_RUN \
|| $TOOTCTL domains purge \
--concurrency "$DB_POOL" \
"$instance"
fi
done < "$TLS_EXPIRED_LOG"
fi
while read -r instance; do
TLS_EXPIRED_TS=$(
date -d "$(
echo Q \
| openssl s_client \
-servername "$instance" \
-connect "${instance}":443 \
2>/dev/null \
| openssl x509 -noout -dates \
| grep 'notAfter' \
| cut -d'=' -f2
)" +%s
)
DATE_DIFF=$(($(date +%s) - TLS_EXPIRED_TS))
if [[ $DATE_DIFF -gt $TLS_EXPIRED_MAX_SEC ]]; then
echo "${instance} has a certificate expired for more than TLS_EXPIRED_MAX_SEC, purging..."
$DRY_RUN \
&& $TOOTCTL domains purge \
--concurrency "$DB_POOL" \
--dry-run \
"$instance"
$DRY_RUN \
|| $TOOTCTL domains purge \
--concurrency "$DB_POOL" \
"$instance"
fi
done < "$TLS_EXPIRED_LOG"
# Log other instances errors, then if they were already in the log, purge them
if grep -q 'https' "$CULL_LOG"; then
grep \
-e 'certificate verify failed' \
-e 'timed out' \
-e 'sslv3 alert handshake failure' \
-e 'TooManyRedirectsError' \
-e 'EndlessRedirectError' \
-e 'HostValidationError' \
"$CULL_LOG" \
| awk '{print $NF}' \
| cut -d'/' -f3 \
| sort -u \
> "$OTHER_ERRORS_LOG"
fi
# Log unjoinable instances, then if they were already in the log, purge them
if grep -q 'not available during the check:' "$CULL_LOG"; then
grep \
-A 9999 \
'not available during the check:' \
"$CULL_LOG" \
| tail -n +2 \
| sed -E 's/\s+//' \
> "$OTHER_ERRORS_LOG"
fi
# Log other instances errors, then if they were already in the log, purge
# them
grep \
-e 'certificate verify failed' \
-e 'timed out' \
-e 'sslv3 alert handshake failure' \
-e 'TooManyRedirectsError' \
"$CULL_LOG" \
| awk '{print $NF}' \
| cut -d'/' -f3 \
| sort -u \
> "$OTHER_ERRORS_LOG"
test -f $PREV_ERRORS_LOG || touch $PREV_ERRORS_LOG
while read -r instance; do
@ -109,7 +93,6 @@ accounts_cull() {
error=false
echo "${instance} was already in error last time your ran tootpaste, trying access..."
curl \
--output /dev/null \
--silent \
--show-error \
--max-time "$INSTANCE_LAST_CHANCE_TIMEOUT" \
@ -126,8 +109,6 @@ accounts_cull() {
|| $TOOTCTL domains purge \
--concurrency "$DB_POOL" \
"$instance"
else
echo "${instance} can now be accessed, not purging!"
fi
fi
done < "$OTHER_ERRORS_LOG"