fix: Health Monitor storage and disk notices, SELinux-safe host backup, Frigate detector keys

This commit is contained in:
MacRimi
2026-09-28 18:18:09 +02:00
parent 33245a423a
commit 297c026c95
22 changed files with 171 additions and 25 deletions
@@ -177,7 +177,7 @@ while IFS= read -r rel; do
if (( ${#state_excludes[@]} )); then
# backup_root lives inside /var/lib/proxmenux/pre-restore.
mkdir -p "$backup_root/$rel" >/dev/null 2>&1 || true
rsync -aAXH "${state_excludes[@]}" "$dst/" "$backup_root/$rel/" >/dev/null 2>&1 || true
rsync -aAXH --filter='-x security.selinux' "${state_excludes[@]}" "$dst/" "$backup_root/$rel/" >/dev/null 2>&1 || true
else
cp -a "$dst" "$backup_root/$rel" >/dev/null 2>&1 || true
fi
@@ -190,7 +190,7 @@ while IFS= read -r rel; do
# copy of the excluded file isn't removed by rsync after being
# skipped from the source side.
if [[ ${#RSYNC_EXCLUDES[@]} -gt 0 ]]; then
if rsync -aAXH "${RSYNC_EXCLUDES[@]}" "${state_excludes[@]}" "$src/" "$dst/" >/dev/null 2>&1; then
if rsync -aAXH --filter='-x security.selinux' "${RSYNC_EXCLUDES[@]}" "${state_excludes[@]}" "$src/" "$dst/" >/dev/null 2>&1; then
((applied++))
[[ "$rel" == "var/lib/proxmenux/backup-jobs" || "$rel" == "var/lib/proxmenux/backup-jobs/"* ]] && jobs_restored=1
(( state_jobs )) && jobs_restored=1
@@ -198,7 +198,7 @@ while IFS= read -r rel; do
((failed++))
fi
else
if rsync -aAXH --delete "${state_excludes[@]}" "$src/" "$dst/" >/dev/null 2>&1; then
if rsync -aAXH --filter='-x security.selinux' --delete "${state_excludes[@]}" "$src/" "$dst/" >/dev/null 2>&1; then
((applied++))
[[ "$rel" == "var/lib/proxmenux/backup-jobs" || "$rel" == "var/lib/proxmenux/backup-jobs/"* ]] && jobs_restored=1
(( state_jobs )) && jobs_restored=1
+3 -3
View File
@@ -1763,7 +1763,7 @@ _rs_apply() {
if (( ${#state_excludes[@]} )); then
# backup_root lives inside /var/lib/proxmenux/pre-restore.
mkdir -p "$backup_root/$rel"
rsync -aAXH "${state_excludes[@]}" "$dst/" "$backup_root/$rel/" 2>/dev/null || true
rsync -aAXH --filter='-x security.selinux' "${state_excludes[@]}" "$dst/" "$backup_root/$rel/" 2>/dev/null || true
else
cp -a "$dst" "$backup_root/$rel" 2>/dev/null || true
fi
@@ -1797,7 +1797,7 @@ _rs_apply() {
)
fi
rsync_extra+=("${state_excludes[@]}")
if rsync -aAXH --delete "${rsync_extra[@]}" "$src/" "$dst/" 2>/dev/null; then
if rsync -aAXH --filter='-x security.selinux' --delete "${rsync_extra[@]}" "$src/" "$dst/" 2>/dev/null; then
((applied++))
[[ "$rel" == "var/lib/proxmenux/backup-jobs" || "$rel" == "var/lib/proxmenux/backup-jobs/"* ]] && jobs_restored=1
[[ "$rel" == "var/lib/proxmenux" && -d "$src/backup-jobs" ]] && jobs_restored=1
@@ -2337,7 +2337,7 @@ _rs_prepare_pending_restore() {
mkdir -p "$(dirname "$dst")" || exit 1
if [[ -d "$src" ]]; then
mkdir -p "$dst" || exit 1
if ! rsync -aAXH --delete "$src/" "$dst/" 2>/dev/null; then
if ! rsync -aAXH --filter='-x security.selinux' --delete "$src/" "$dst/" 2>/dev/null; then
msg_error "$(translate "Could not stage pending restore path:") $rel"
exit 1
fi
@@ -680,8 +680,10 @@ hb_prepare_staging() {
target="$staging_root/rootfs/$rel"
if [[ -d "$p" ]]; then
mkdir -p "$target"
# The SELinux label belongs to the host that wrote the file: pmxcfs
# has none, and rsync cannot remove the one /tmp gives the copy.
local -a rsync_opts=(
-aAXH --numeric-ids
-aAXH --numeric-ids --filter='-x security.selinux'
)
# /var/lib/pve-cluster: skip the raw config.db and its WAL/SHM