From 2a9b918f727c212b87209859bf3897579edc261a Mon Sep 17 00:00:00 2001 From: Erik Arvstedt Date: Fri, 23 Oct 2020 10:45:49 +0200 Subject: [PATCH] generate-secrets: always run with Bash, stop on errors --- pkgs/generate-secrets/default.nix | 2 +- pkgs/generate-secrets/generate-secrets.sh | 2 ++ 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/generate-secrets/default.nix b/pkgs/generate-secrets/default.nix index e633876..5f88019 100644 --- a/pkgs/generate-secrets/default.nix +++ b/pkgs/generate-secrets/default.nix @@ -9,7 +9,7 @@ let exec ${pkgs.python3}/bin/python ${rpcauthSrc} "$@" ''; in -writeScript "generate-secrets" '' +writers.writeBash "generate-secrets" '' export PATH=${lib.makeBinPath [ coreutils apg openssl gnugrep rpcauth ]} . ${./generate-secrets.sh} ${./openssl.cnf} '' diff --git a/pkgs/generate-secrets/generate-secrets.sh b/pkgs/generate-secrets/generate-secrets.sh index 4255289..229b774 100755 --- a/pkgs/generate-secrets/generate-secrets.sh +++ b/pkgs/generate-secrets/generate-secrets.sh @@ -1,5 +1,7 @@ #!/usr/bin/env bash +set -euo pipefail + opensslConf=${1:-openssl.cnf} makePasswordSecret() {