fix(bootstrap): open up a nano-only config dir an older run left 0750
write_nano_config creates a missing /etc/felis as 0755, but it left an existing one alone. On a nano-only host an older installer made that directory with a bare mkdir -p, so under a root umask of 027 it is 0750. The DynamicUser unit cannot search it, so felis-nano cannot read its config, and a re-run stops at the service check instead of repairing the directory. An existing directory is now set to 0755 unless it holds the full install's secrets.env or bootstrap.done. The full install locks the directory to 0700 and writes secrets.env right after, so its directory keeps that mode, and install_nano_service still reports the lockout rather than this widening it. The mode cases run only where chmod works; on a filesystem that ignores it the harness skips them.
This commit is contained in:
2 files changed
+21
-9
No files matched your search
+9
-4
@@ -2358,10 +2358,15 @@ acquire_nano_binary() {
|
||||
write_nano_config() {
|
||||
local target="${STATE_DIR}/felis.toml"
|
||||
# The unit is a DynamicUser, so it can read felis.toml only if it can search this
|
||||
# directory. The mode is explicit because a hardened root umask (027) would leave it 0750.
|
||||
# An existing directory keeps its mode: the full install locks it to 0700 for its secrets,
|
||||
# and install_nano_service reports that lockout rather than this widening it.
|
||||
[ -d "$STATE_DIR" ] || mkdir -p -m 0755 "$STATE_DIR"
|
||||
# directory. The mode is explicit because a hardened root umask (027) would leave it 0750,
|
||||
# which is what older installers did to nano-only hosts. Only the full install keeps its
|
||||
# own 0700: that directory holds secrets, and install_nano_service reports the lockout
|
||||
# rather than this widening it.
|
||||
if [ ! -d "$STATE_DIR" ]; then
|
||||
mkdir -p -m 0755 "$STATE_DIR"
|
||||
elif [ ! -e "$SECRETS_ENV" ] && [ ! -e "$BOOTSTRAP_DONE" ]; then
|
||||
chmod 0755 "$STATE_DIR"
|
||||
fi
|
||||
if [ -e "$target" ]; then
|
||||
ok "config already present at ${target}; leaving it (edit it to add [[auth_source]] roots)"
|
||||
return 0
|
||||
|
||||
Reference in new issue
Block a user