fix(bootstrap): create the nano config dir world-searchable
felis-nano runs as a systemd DynamicUser, so it can read /etc/felis/felis.toml only if others may search /etc/felis. write_nano_config made the directory with a bare mkdir -p, which takes its mode from root's umask. On a host hardened to umask 027 that is 0750: nano exits on "permission denied", the unit restarts every five seconds, and no login gets through. A missing directory is now created 0755 explicitly. An existing one keeps its mode, because the full install sets it to 0700 to protect its secrets and widening that from the nano path would expose them. A nano unit locked out that way is left for the install to report. The harness runs the extracted function under umask 027 and checks both cases. Reverting to the bare mkdir fails the first; an unconditional chmod 0755 fails the second. The mode checks skip on filesystems that ignore chmod, such as Git Bash on NTFS.
This commit is contained in:
2 files changed
+32
-1
No files matched your search
+5
-1
@@ -2300,7 +2300,11 @@ acquire_nano_binary() {
|
||||
|
||||
write_nano_config() {
|
||||
local target="${STATE_DIR}/felis.toml"
|
||||
mkdir -p "$STATE_DIR"
|
||||
# The unit is a DynamicUser, so it can read felis.toml only if it can search this
|
||||
# directory. The mode is explicit because a hardened root umask (027) would leave it 0750.
|
||||
# An existing directory keeps its mode: the full install locks it to 0700 for its secrets,
|
||||
# and install_nano_service reports that lockout rather than this widening it.
|
||||
[ -d "$STATE_DIR" ] || mkdir -p -m 0755 "$STATE_DIR"
|
||||
if [ -e "$target" ]; then
|
||||
ok "config already present at ${target}; leaving it (edit it to add [[auth_source]] roots)"
|
||||
return 0
|
||||
|
||||
Reference in new issue
Block a user