fix(operator): 游戏 Pod 改以 UID 1000 运行并丢弃全部能力,prepare-data 初始化容器修正旧存档属主

This commit is contained in:
Lemon-miaow committed 2026-09-24 16:23:49 +08:00
1 parent c1796bea17
commit 346a93921e
25 files changed
+555 -91

No files matched your search

+15
View File
@@ -10,6 +10,8 @@ import (
"os"
"path"
"time"
"felis.lolicon.best/internal/naming"
)
// The three operations the editor supports. The set is deliberately closed and
@@ -343,9 +345,22 @@ func write(r *os.Root, path string, content []byte) Result {
if err := f.Close(); err != nil {
return failure(err, path)
}
// The Job runs as root, so a file it just created is root's. The server runs as
// the game uid and could read it (0644) but never rewrite it — a config the
// panel authored that Paper then fails to save. Best effort: the content has
// landed and reporting failure would lie, and the server's prepare-data
// initContainer re-owns anything left behind on its next start anyway.
_ = ownWritten(r, path)
return Result{}
}
// ownWritten hands a written file to the game uid. os.Root.Chown follows a symlink
// only within the root, so this can never re-own a file outside the mount. A var so
// tests, which cannot chown, can observe the call.
var ownWritten = func(r *os.Root, name string) error {
return r.Chown(name, int(naming.GameUID), int(naming.GameGID))
}
// failure maps a filesystem error onto a caller-facing Result code. Anything that
// is genuinely "nothing is there" becomes not_found; EVERYTHING else — including
// every os.Root containment refusal — becomes bad_path.