# Extract temporary password lines from local MySQL err log into stash (no stdout secrets). $ErrorActionPreference = "Continue" $mysql = "C:\yutongda\tools\mysql-8.0.39-winx64\bin\mysql.exe" $err = Get-ChildItem "C:\yutongda\data\mysql" -Filter "*.err" -EA SilentlyContinue | Select-Object -First 5 foreach ($f in $err) { Write-Output ("errfile=" + $f.FullName + " size=" + $f.Length) $hits = Select-String -Path $f.FullName -Pattern "temporary password|root@localhost|Password" -EA SilentlyContinue Write-Output ("hits=" + @($hits).Count) $i = 0 foreach ($h in $hits) { $i++ $line = $h.Line # classify without printing secret $kind = "other" $pass = $null if ($line -match '(?i)A temporary password for root@localhost:\s*(\S+)') { $kind = "temp_root" $pass = $Matches[1] } elseif ($line -match '(?i)temporary password[^\r\n]*?:\s*(\S+)') { $kind = "temp_generic" $pass = $Matches[1] } elseif ($line -match '(?i)root@localhost') { $kind = "root_mention" } Write-Output ("hit#$i lineNo=$($h.LineNumber) kind=$kind passLen=$(if($pass){$pass.Length}else{0})") if ($pass) { $stash = "E:\wwwroot\ops\.mysql_root_cand_$i.tmp" Set-Content $stash -Value $pass -Encoding ascii -NoNewline } } } Write-Output "=== try all stashed cand files ===" function Test-Root([string]$pass) { foreach ($hostArgs in @(@(), @("-h127.0.0.1","-P3306"))) { $argList = @() + $hostArgs + @("-uroot","-p$pass","--connect-timeout=8","--batch","-N","-e","SELECT 1") $out = & $mysql @argList 2>&1 $text = ($out | ForEach-Object { "$_" }) -join "`n" if ($text -match "ERROR\s+\d+") { continue } $lines = $out | ForEach-Object { "$_".Trim() } | Where-Object { $_ -ne "" -and $_ -notmatch "Warning" } if ($lines -contains "1") { return $true } } return $false } Get-ChildItem "E:\wwwroot\ops\.mysql_root_cand_*.tmp" -EA SilentlyContinue | ForEach-Object { $p = (Get-Content $_.FullName -Raw).Trim() $ok = Test-Root $p Write-Output ("try=$($_.Name) len=$($p.Length) ok=$ok") if ($ok) { Copy-Item $_.FullName "E:\wwwroot\ops\.mysql_root_stash.tmp" -Force Write-Output "STASHED_OK" } } # Also dump last 30 err lines with passwords redacted to understand init state Write-Output "=== err tail redacted ===" $errFile = Get-ChildItem "C:\yutongda\data\mysql" -Filter "*.err" | Sort-Object LastWriteTime -Descending | Select-Object -First 1 if ($errFile) { Get-Content $errFile.FullName -Tail 40 | ForEach-Object { $_ -replace '(?i)(password[^\r\n]*?:\s*)\S+','$1***' -replace '(?i)(IDENTIFIED BY\s+)''[^'']+''','$1***' } } Write-Output "DONE"