mirror of
https://github.com/xpipe-io/xpipe.git
synced 2026-10-05 06:37:47 +00:00
Various fixes
This commit is contained in:
@@ -34,6 +34,11 @@ public class AppLocalTemp {
|
||||
|
||||
try {
|
||||
if (Files.isDirectory(temp)) {
|
||||
var owner = Files.getOwner(temp).getName();
|
||||
if (!owner.equals(AppSystemInfo.ofLinux().getUser())) {
|
||||
throw new IOException("Invalid temp dir owner for " + temp);
|
||||
}
|
||||
|
||||
Files.setPosixFilePermissions(temp, PosixFilePermissions.fromString("rwx------"));
|
||||
}
|
||||
return temp;
|
||||
|
||||
@@ -304,7 +304,7 @@ public class AppProperties {
|
||||
private static Path getLocalBeaconAuthFile(boolean staging) {
|
||||
if (OsType.ofLocal() == OsType.LINUX) {
|
||||
var name = AppSystemInfo.ofCurrent().getUser();
|
||||
return AppSystemInfo.ofCurrent().getTemp().resolve(staging ? "xpipe-ptb" : "xpipe", name, "beacon-auth");
|
||||
return AppSystemInfo.ofCurrent().getTemp().resolve((staging ? "xpipe-ptb" : "xpipe") + "-" + AppSystemInfo.ofLinux().getUser(), name, "beacon-auth");
|
||||
} else {
|
||||
var path = AppSystemInfo.ofCurrent().getTemp().resolve(staging ? "xpipe-ptb" : "xpipe", "beacon-auth");
|
||||
return path;
|
||||
|
||||
@@ -17,11 +17,38 @@ public class ShellTemp {
|
||||
var temp = proc.getSystemTemporaryDirectory();
|
||||
var base = temp.join(AppNames.ofCurrent().getKebapName() + "-" + proc.view().user());
|
||||
proc.view().mkdir(base);
|
||||
// We have to make sure that we own this directory, chmod will if not
|
||||
// This command should work in all shells
|
||||
var chmodSuccess = proc.command("chmod 700 " + proc.getShellDialect().fileArgument(base)).executeAndCheck();
|
||||
if (!chmodSuccess) {
|
||||
throw new IOException("Unexpected directory ownership and permissions for " + base);
|
||||
if (!proc.view().isRoot()) {
|
||||
// We have to make sure that we own this directory, chmod will fail if not
|
||||
// This command should work in all shells
|
||||
var hasChmod = proc.view().findProgram("chmod").isPresent();
|
||||
if (hasChmod) {
|
||||
var chmodSuccess = proc.command("chmod 700 " + proc.getShellDialect().fileArgument(base)).executeAndCheck();
|
||||
if (!chmodSuccess) {
|
||||
throw new IOException("Unexpected directory ownership and permissions for " + base);
|
||||
}
|
||||
}
|
||||
} else {
|
||||
var hasLs = proc.view().findProgram("ls").isPresent();
|
||||
if (hasLs) {
|
||||
var lsOut = proc.command("ls -ldn " + proc.getShellDialect().fileArgument(base)).readStdoutIfPossible();
|
||||
if (lsOut.isPresent()) {
|
||||
var split = lsOut.get().split("\\s+");
|
||||
if (split.length >= 3) {
|
||||
if (!split[2].equals("0")) {
|
||||
throw new IOException("Unexpected directory ownership for " + base);
|
||||
}
|
||||
|
||||
var hasChmod = proc.view().findProgram("chmod").isPresent();
|
||||
if (hasChmod) {
|
||||
var chmodSuccess = proc.command("chmod 700 " + proc.getShellDialect().fileArgument(base)).executeAndCheck();
|
||||
if (!chmodSuccess) {
|
||||
throw new IOException("Unexpected directory ownership and permissions for " + base);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
return sub != null ? base.join(sub) : base;
|
||||
} else {
|
||||
|
||||
Reference in New Issue
Block a user