lib.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429
  1. <?php
  2. // DEPRECATED: The bundled managed backup server is deprecated and unmaintained.
  3. // It is kept for reference only and will be removed in a future release.
  4. // Do not deploy it for new installations.
  5. declare(strict_types=1);
  6. // Shared helpers for the backup server. Included by upload.php and manage.php.
  7. $backupServerConfigFile = __DIR__ . "/config.php";
  8. if (is_file($backupServerConfigFile)) {
  9. require_once $backupServerConfigFile;
  10. }
  11. if (!defined("BACKUP_SERVER_RETENTION")) {
  12. define("BACKUP_SERVER_RETENTION", 30);
  13. }
  14. if (!defined("BACKUP_SERVER_BACKUP_DIR")) {
  15. define("BACKUP_SERVER_BACKUP_DIR", __DIR__ . "/backups/");
  16. }
  17. if (!defined("BACKUP_SERVER_INDEX_FILE")) {
  18. define("BACKUP_SERVER_INDEX_FILE", rtrim((string) BACKUP_SERVER_BACKUP_DIR, "/\\") . "/index.json");
  19. }
  20. if (!defined("BACKUP_SERVER_SETTINGS_FILE")) {
  21. define("BACKUP_SERVER_SETTINGS_FILE", rtrim((string) BACKUP_SERVER_BACKUP_DIR, "/\\") . "/settings.json");
  22. }
  23. if (!defined("BACKUP_SERVER_S3_ENABLED")) {
  24. define("BACKUP_SERVER_S3_ENABLED", false);
  25. }
  26. if (!defined("BACKUP_SERVER_S3_ENDPOINT")) {
  27. define("BACKUP_SERVER_S3_ENDPOINT", "");
  28. }
  29. if (!defined("BACKUP_SERVER_S3_REGION")) {
  30. define("BACKUP_SERVER_S3_REGION", "");
  31. }
  32. if (!defined("BACKUP_SERVER_S3_BUCKET")) {
  33. define("BACKUP_SERVER_S3_BUCKET", "");
  34. }
  35. if (!defined("BACKUP_SERVER_S3_PREFIX")) {
  36. define("BACKUP_SERVER_S3_PREFIX", "");
  37. }
  38. if (!defined("BACKUP_SERVER_S3_ACCESS_KEY")) {
  39. define("BACKUP_SERVER_S3_ACCESS_KEY", "");
  40. }
  41. if (!defined("BACKUP_SERVER_S3_SECRET_KEY")) {
  42. define("BACKUP_SERVER_S3_SECRET_KEY", "");
  43. }
  44. if (!defined("BACKUP_SERVER_S3_PATH_STYLE")) {
  45. define("BACKUP_SERVER_S3_PATH_STYLE", false);
  46. }
  47. if (!defined("BACKUP_SERVER_S3_TIMEOUT")) {
  48. define("BACKUP_SERVER_S3_TIMEOUT", 120);
  49. }
  50. if (!defined("BACKUP_SERVER_S3_RETENTION")) {
  51. define("BACKUP_SERVER_S3_RETENTION", 365);
  52. }
  53. if (!defined("BACKUP_SERVER_LOG_FILE")) {
  54. define("BACKUP_SERVER_LOG_FILE", rtrim((string) BACKUP_SERVER_BACKUP_DIR, "/\\") . "/s3.log");
  55. }
  56. require_once __DIR__ . "/s3.php";
  57. function backupServerEnsureDirectory(string $dir): void
  58. {
  59. if (!is_dir($dir) && !mkdir($dir, 02775, true) && !is_dir($dir)) {
  60. throw new RuntimeException("Directory cannot be created: " . $dir);
  61. }
  62. @chmod($dir, 02775);
  63. }
  64. function backupServerReadJsonFile(string $file): array
  65. {
  66. if (!is_file($file)) {
  67. return [];
  68. }
  69. $decoded = json_decode((string) file_get_contents($file), true);
  70. if (!is_array($decoded)) {
  71. throw new RuntimeException("JSON file is invalid: " . basename($file));
  72. }
  73. return $decoded;
  74. }
  75. function backupServerWriteJsonFile(string $file, array $data): void
  76. {
  77. backupServerEnsureDirectory(dirname($file));
  78. $json = json_encode(
  79. $data,
  80. JSON_PRETTY_PRINT | JSON_UNESCAPED_SLASHES | JSON_UNESCAPED_UNICODE,
  81. );
  82. if ($json === false) {
  83. throw new RuntimeException("JSON cannot be encoded.");
  84. }
  85. $tmpFile = $file . ".tmp";
  86. if (file_put_contents($tmpFile, $json . PHP_EOL, LOCK_EX) === false) {
  87. throw new RuntimeException("JSON cannot be written.");
  88. }
  89. @chmod($tmpFile, 0664);
  90. if (!rename($tmpFile, $file)) {
  91. @unlink($tmpFile);
  92. throw new RuntimeException("JSON cannot be saved.");
  93. }
  94. @chmod($file, 0664);
  95. }
  96. function backupServerReadIndex(): array
  97. {
  98. $index = backupServerReadJsonFile((string) BACKUP_SERVER_INDEX_FILE);
  99. $backups = isset($index["backups"]) && is_array($index["backups"])
  100. ? $index["backups"]
  101. : [];
  102. return ["backups" => array_values($backups)];
  103. }
  104. function backupServerWriteIndex(array $backups): void
  105. {
  106. backupServerWriteJsonFile((string) BACKUP_SERVER_INDEX_FILE, [
  107. "backups" => array_values($backups),
  108. ]);
  109. }
  110. function backupServerValidateInstance(string $instance): string
  111. {
  112. $instance = trim($instance);
  113. if (
  114. $instance === "" ||
  115. strlen($instance) > 120 ||
  116. preg_match('/^[A-Za-z0-9][A-Za-z0-9._-]*$/', $instance) !== 1
  117. ) {
  118. throw new RuntimeException("Invalid instance identifier.");
  119. }
  120. return $instance;
  121. }
  122. function backupServerInstanceDir(string $instance): string
  123. {
  124. return rtrim((string) BACKUP_SERVER_BACKUP_DIR, "/\\") . DIRECTORY_SEPARATOR . $instance;
  125. }
  126. function backupServerBackupPath(string $instance, string $filename): string
  127. {
  128. return backupServerInstanceDir($instance) . DIRECTORY_SEPARATOR . $filename;
  129. }
  130. function backupServerGetSettings(): array
  131. {
  132. $settings = backupServerReadJsonFile((string) BACKUP_SERVER_SETTINGS_FILE);
  133. $retention = isset($settings["retention"])
  134. ? max(1, (int) $settings["retention"])
  135. : max(1, (int) BACKUP_SERVER_RETENTION);
  136. $s3Retention = isset($settings["s3_retention"])
  137. ? max(1, (int) $settings["s3_retention"])
  138. : max(1, (int) BACKUP_SERVER_S3_RETENTION);
  139. $instances =
  140. isset($settings["instances"]) && is_array($settings["instances"])
  141. ? $settings["instances"]
  142. : [];
  143. $allowedInstances = [];
  144. foreach ($instances as $instance) {
  145. try {
  146. $allowedInstances[] = backupServerValidateInstance((string) $instance);
  147. } catch (Throwable $exception) {
  148. continue;
  149. }
  150. }
  151. $allowedInstances = array_values(array_unique($allowedInstances));
  152. sort($allowedInstances);
  153. return [
  154. "retention" => $retention,
  155. "s3_retention" => $s3Retention,
  156. "instances" => $allowedInstances,
  157. ];
  158. }
  159. function backupServerWriteSettings(array $settings): void
  160. {
  161. $instances =
  162. isset($settings["instances"]) && is_array($settings["instances"])
  163. ? $settings["instances"]
  164. : backupServerGetSettings()["instances"];
  165. $allowedInstances = [];
  166. foreach ($instances as $instance) {
  167. $allowedInstances[] = backupServerValidateInstance((string) $instance);
  168. }
  169. $allowedInstances = array_values(array_unique($allowedInstances));
  170. sort($allowedInstances);
  171. backupServerWriteJsonFile((string) BACKUP_SERVER_SETTINGS_FILE, [
  172. "retention" => max(1, (int) ($settings["retention"] ?? BACKUP_SERVER_RETENTION)),
  173. "s3_retention" => max(1, (int) ($settings["s3_retention"] ?? BACKUP_SERVER_S3_RETENTION)),
  174. "instances" => $allowedInstances,
  175. ]);
  176. }
  177. function backupServerLog(string $message, array $context = []): void
  178. {
  179. $line = date(DATE_ATOM) . " " . $message;
  180. $encoded = @json_encode($context, JSON_UNESCAPED_SLASHES | JSON_UNESCAPED_UNICODE);
  181. if (is_string($encoded) && $encoded !== "[]") {
  182. $line .= " " . $encoded;
  183. }
  184. @file_put_contents((string) BACKUP_SERVER_LOG_FILE, $line . PHP_EOL, FILE_APPEND | LOCK_EX);
  185. }
  186. function backupServerUpdateIndexRecord(string $instance, string $filename, callable $update): void
  187. {
  188. $index = backupServerReadIndex();
  189. foreach ($index["backups"] as $position => $backup) {
  190. if (
  191. is_array($backup) &&
  192. ($backup["instance"] ?? "") === $instance &&
  193. ($backup["filename"] ?? "") === $filename
  194. ) {
  195. $index["backups"][$position] = $update($backup);
  196. }
  197. }
  198. backupServerWriteIndex($index["backups"]);
  199. }
  200. function backupServerIndexInstances(): array
  201. {
  202. $instances = [];
  203. foreach (backupServerReadIndex()["backups"] as $backup) {
  204. if (is_array($backup)) {
  205. $instance = (string) ($backup["instance"] ?? "");
  206. if ($instance !== "") {
  207. $instances[$instance] = true;
  208. }
  209. }
  210. }
  211. return array_keys($instances);
  212. }
  213. // Uploads every local backup of the instance that is not yet confirmed in S3,
  214. // oldest first. Serves both the immediate upload after receiving a backup and
  215. // the opportunistic retry of earlier failures. Stops at the first failure
  216. // because the endpoint is then most likely unreachable.
  217. function backupServerSyncInstanceS3(string $instance): array
  218. {
  219. $result = ["uploaded" => 0, "pending" => 0, "error" => null];
  220. if (!backupS3Enabled()) {
  221. return $result;
  222. }
  223. $pending = [];
  224. foreach (backupServerReadIndex()["backups"] as $backup) {
  225. if (!is_array($backup) || ($backup["instance"] ?? "") !== $instance) {
  226. continue;
  227. }
  228. if (!empty($backup["s3_uploaded_at"])) {
  229. continue;
  230. }
  231. $filename = basename((string) ($backup["filename"] ?? ""));
  232. if ($filename === "" || !is_file(backupServerBackupPath($instance, $filename))) {
  233. continue;
  234. }
  235. $backup["filename"] = $filename;
  236. $pending[] = $backup;
  237. }
  238. usort($pending, function ($left, $right) {
  239. return strcmp((string) ($left["uploaded_at"] ?? ""), (string) ($right["uploaded_at"] ?? ""));
  240. });
  241. foreach ($pending as $position => $backup) {
  242. $filename = (string) $backup["filename"];
  243. $key = (string) ($backup["s3_key"] ?? "");
  244. if ($key === "") {
  245. $key = backupS3ObjectKey($instance, $filename);
  246. }
  247. try {
  248. backupS3PutFile(backupServerBackupPath($instance, $filename), $key);
  249. } catch (Throwable $exception) {
  250. $result["pending"] = count($pending) - $position;
  251. $result["error"] = $exception->getMessage();
  252. backupServerUpdateIndexRecord($instance, $filename, function (array $record) use ($key, $exception) {
  253. $record["s3_key"] = $key;
  254. $record["s3_last_error"] = $exception->getMessage();
  255. $record["s3_last_attempt_at"] = date(DATE_ATOM);
  256. return $record;
  257. });
  258. backupServerLog("S3 upload failed", [
  259. "instance" => $instance,
  260. "filename" => $filename,
  261. "key" => $key,
  262. "error" => $exception->getMessage(),
  263. ]);
  264. return $result;
  265. }
  266. backupServerUpdateIndexRecord($instance, $filename, function (array $record) use ($key) {
  267. $record["s3_key"] = $key;
  268. $record["s3_uploaded_at"] = date(DATE_ATOM);
  269. unset($record["s3_last_error"], $record["s3_last_attempt_at"], $record["s3_expired"]);
  270. return $record;
  271. });
  272. $result["uploaded"]++;
  273. }
  274. return $result;
  275. }
  276. // Applies both retention tiers for one instance. S3 keeps the newest
  277. // s3_retention archived backups; local keeps the newest retention copies but
  278. // never deletes a file whose S3 upload is still pending.
  279. function backupServerApplyRetention(string $instance): void
  280. {
  281. $index = backupServerReadIndex();
  282. $settings = backupServerGetSettings();
  283. $s3Enabled = backupS3Enabled();
  284. $instanceBackups = [];
  285. $otherBackups = [];
  286. foreach ($index["backups"] as $backup) {
  287. if (!is_array($backup)) {
  288. continue;
  289. }
  290. if (($backup["instance"] ?? "") === $instance) {
  291. $instanceBackups[] = $backup;
  292. } else {
  293. $otherBackups[] = $backup;
  294. }
  295. }
  296. usort($instanceBackups, function ($left, $right) {
  297. return strcmp((string) ($right["uploaded_at"] ?? ""), (string) ($left["uploaded_at"] ?? ""));
  298. });
  299. if ($s3Enabled) {
  300. $archivedSeen = 0;
  301. foreach ($instanceBackups as $position => $backup) {
  302. if (empty($backup["s3_uploaded_at"])) {
  303. continue;
  304. }
  305. $archivedSeen++;
  306. if ($archivedSeen <= $settings["s3_retention"]) {
  307. continue;
  308. }
  309. $filename = basename((string) ($backup["filename"] ?? ""));
  310. $key = (string) ($backup["s3_key"] ?? "");
  311. if ($key === "" && $filename !== "") {
  312. $key = backupS3ObjectKey($instance, $filename);
  313. }
  314. try {
  315. if ($key !== "") {
  316. backupS3DeleteObject($key);
  317. }
  318. } catch (Throwable $exception) {
  319. backupServerLog("S3 retention delete failed", [
  320. "instance" => $instance,
  321. "filename" => $filename,
  322. "key" => $key,
  323. "error" => $exception->getMessage(),
  324. ]);
  325. continue;
  326. }
  327. unset($backup["s3_uploaded_at"], $backup["s3_key"]);
  328. $backup["s3_expired"] = true;
  329. $instanceBackups[$position] = $backup;
  330. }
  331. }
  332. $localSeen = 0;
  333. $kept = [];
  334. foreach ($instanceBackups as $backup) {
  335. $filename = basename((string) ($backup["filename"] ?? ""));
  336. $path = $filename !== "" ? backupServerBackupPath($instance, $filename) : "";
  337. $localExists = $path !== "" && is_file($path);
  338. $inS3 = !empty($backup["s3_uploaded_at"]);
  339. if (!$localExists) {
  340. if ($inS3) {
  341. $kept[] = $backup;
  342. }
  343. // Present in neither store: drop the orphaned record.
  344. continue;
  345. }
  346. $localSeen++;
  347. if ($localSeen <= $settings["retention"]) {
  348. $kept[] = $backup;
  349. continue;
  350. }
  351. if ($inS3) {
  352. @unlink($path);
  353. $backup["local_deleted_at"] = date(DATE_ATOM);
  354. $kept[] = $backup;
  355. continue;
  356. }
  357. if ($s3Enabled && empty($backup["s3_expired"])) {
  358. // The only copy lives locally until the S3 upload succeeds.
  359. $kept[] = $backup;
  360. continue;
  361. }
  362. // S3 disabled (legacy behavior) or the backup already aged out of S3.
  363. @unlink($path);
  364. }
  365. backupServerWriteIndex(array_merge($otherBackups, $kept));
  366. }
  367. function backupServerApplyRetentionAll(): void
  368. {
  369. foreach (backupServerIndexInstances() as $instance) {
  370. backupServerApplyRetention($instance);
  371. }
  372. }