From 7633f1e790e6cede791d5a21b7c2bb50551cceb5 Mon Sep 17 00:00:00 2001 From: Anton Georgiev Date: Mon, 14 Sep 2026 11:05:56 -0400 Subject: [PATCH 1/2] Accept apt release-info changes so upgrades cannot fail silently apt refuses to use a repository whose Release Origin or Label changed until the change is accepted once, and a rejected fetch leaves the previously cached package lists in place. bbb-install.sh called bare `apt-get update` in five places and has no `set -e`, so the rejection was ignored: the dist-upgrade that follows found nothing new, need_pkg saw everything already installed, and the script restarted the server and reported success while leaving it on its old version. This is not hypothetical. noble-400 gained Origin: and Label: on 2026-09-04 (they had been empty, inherited from a verbatim Release copy). Every 4.0 server whose apt cache predates that is blocked, and re-running this script cannot clear it - which is how a server asked for 4.0.0-rc.3 and stayed on rc.2 with a clean-looking run. Route the five call sites through a helper that passes --allow-releaseinfo-change. Because the installer is fetched fresh from GitHub on every run, this also unsticks servers that are already blocked: the next normal upgrade accepts the pending change and proceeds, with no per-server intervention. Verified against apt 2.8.3 with a local HTTP repo. Starting from a cache holding the old empty-Origin Release and a server at rc.2, publishing rc.4 with Origin/Label set gives two blocking errors and the cache stays at rc.2 under the current code; the helper takes the same cache to rc.4. The helper warns rather than aborting. `apt-get update` returns non-zero for any configured repository, so making it fatal would turn a transient Ubuntu mirror hiccup into a failed install - a worse regression than the one being fixed. The silent-success path is closed either way, since the known cause is now handled and anything else is reported. Fixes #851 --- bbb-install.sh | 18 +++++++++++++----- 1 file changed, 13 insertions(+), 5 deletions(-) diff --git a/bbb-install.sh b/bbb-install.sh index 1eabd86..8208359 100644 --- a/bbb-install.sh +++ b/bbb-install.sh @@ -321,7 +321,7 @@ main() { update-java-alternatives -s java-1.21.0-openjdk-amd64 - apt-get update + apt_update apt-get -y -o Dpkg::Options::="--force-confdef" -o Dpkg::Options::="--force-confnew" dist-upgrade need_pkg bigbluebutton @@ -531,6 +531,14 @@ err() { exit 1 } +apt_update() { + # --allow-releaseinfo-change: without it a changed Release Origin/Label makes + # apt keep the stale lists, so the dist-upgrade below silently upgrades nothing. + if ! apt-get update --allow-releaseinfo-change "$@"; then + say "WARNING: apt-get update reported errors; package lists may be stale" >&2 + fi +} + usage_err() { say "$1" >&2 usage @@ -665,7 +673,7 @@ need_pkg() { while fuser /var/lib/dpkg/lock >/dev/null 2>&1; do echo "Sleeping for 1 second because of dpkg lock"; sleep 1; done if [ ! "$SOURCES_FETCHED" = true ]; then - apt-get update + apt_update SOURCES_FETCHED=true fi @@ -1505,7 +1513,7 @@ install_docker() { echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu \ $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null - apt-get update + apt_update need_pkg docker-ce docker-ce-cli containerd.io fi if ! which docker; then err "Docker did not install"; fi @@ -1536,7 +1544,7 @@ install_ssl() { mkdir -p /etc/nginx/ssl if [ -z "$PROVIDED_CERTIFICATE" ]; then - apt-get update + apt_update need_pkg certbot if [[ -f "/etc/letsencrypt/live/$HOST/fullchain.pem" ]] && [[ -f "/etc/letsencrypt/renewal/$HOST.conf" ]] \ @@ -1867,7 +1875,7 @@ HERE install_coturn() { - apt-get update + apt_update apt-get -y -o Dpkg::Options::="--force-confdef" -o Dpkg::Options::="--force-confnew" dist-upgrade need_pkg software-properties-common certbot From e24c1b93586214f24d78fe7d99e8e020d36894ff Mon Sep 17 00:00:00 2001 From: Anton Georgiev Date: Mon, 14 Sep 2026 11:50:16 -0400 Subject: [PATCH 2/2] Drop the unused argument pass-through from apt_update Differential ShellCheck failed on #852 with six new findings: SC2120 on the function itself (references arguments, but none are ever passed) and SC2119 at each of the five call sites, suggesting the callers forward the script's own arguments. The "$@" was speculative. No caller passes anything to apt_update, so it expanded to nothing everywhere and removing it changes no behaviour. Baseline on v4.0.x-release is a single pre-existing SC2086; with this the branch reports that same single finding and introduces none. --- bbb-install.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/bbb-install.sh b/bbb-install.sh index 8208359..9ea6e94 100644 --- a/bbb-install.sh +++ b/bbb-install.sh @@ -534,7 +534,7 @@ err() { apt_update() { # --allow-releaseinfo-change: without it a changed Release Origin/Label makes # apt keep the stale lists, so the dist-upgrade below silently upgrades nothing. - if ! apt-get update --allow-releaseinfo-change "$@"; then + if ! apt-get update --allow-releaseinfo-change; then say "WARNING: apt-get update reported errors; package lists may be stale" >&2 fi }