修复目录权限问题

This commit is contained in:
ryan
2026-06-22 23:21:04 +08:00
parent 8ed91dbf97
commit 49eae80c78
6 changed files with 57 additions and 2 deletions
+18
View File
@@ -302,6 +302,9 @@ func (m *Manager) ensureOpenRestyWorkerReadAccess() error {
if pidPath := m.pidRuntimePath(); pidPath != "" {
targets = append(targets, filepath.Dir(pidPath))
}
if proxyCacheDir := m.proxyCacheRuntimeDir(); proxyCacheDir != "" {
targets = append(targets, proxyCacheDir)
}
seen := make(map[string]struct{}, len(targets))
for _, target := range targets {
cleaned := filepath.Clean(strings.TrimSpace(target))
@@ -1263,6 +1266,14 @@ func (m *Manager) renderMainConfig(content string) string {
}
}
}
if proxyCacheDir := m.proxyCacheRuntimeDir(); proxyCacheDir != "" {
slashProxyCache := filepath.ToSlash(proxyCacheDir)
rendered = strings.ReplaceAll(rendered, openrestyrender.ProxyCachePathPlaceholder, slashProxyCache)
rendered = strings.ReplaceAll(rendered, "/var/cache/openresty", slashProxyCache)
if err := os.MkdirAll(proxyCacheDir, nginxDirPerm); err != nil {
slog.Warn("ensure proxy cache directory failed", "path", proxyCacheDir, "error", err)
}
}
if luaDir := m.luaRuntimePath(); luaDir != "" {
rendered = strings.ReplaceAll(rendered, openrestyrender.LuaDirPlaceholder, luaDir)
}
@@ -1398,6 +1409,13 @@ func (m *Manager) nginxCacheRuntimeDir() string {
return ""
}
func (m *Manager) proxyCacheRuntimeDir() string {
if varRoot := m.varRuntimeDir(); varRoot != "" {
return filepath.Join(varRoot, "cache", "openflare_proxy")
}
return ""
}
func (m *Manager) luaRuntimePath() string {
if strings.TrimSpace(m.NginxLuaDir) == "" {
return ""
@@ -0,0 +1,18 @@
// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
package config_version
import (
"testing"
openrestyrender "github.com/Rain-kl/Wavelet/pkg/render/openresty"
"github.com/stretchr/testify/assert"
)
func TestNormalizeProxyCachePathForSnapshot(t *testing.T) {
assert.Equal(t, "/var/cache/openresty", normalizeProxyCachePathForSnapshot(false, "/var/cache/openresty"))
assert.Equal(t, openrestyrender.ProxyCachePathPlaceholder, normalizeProxyCachePathForSnapshot(true, "/var/cache/openresty"))
assert.Equal(t, openrestyrender.ProxyCachePathPlaceholder, normalizeProxyCachePathForSnapshot(true, ""))
assert.Equal(t, "/data/var/cache/custom", normalizeProxyCachePathForSnapshot(true, "/data/var/cache/custom"))
}
@@ -495,7 +495,7 @@ func buildOpenRestyConfigSnapshot(ctx context.Context) openRestyConfigSnapshot {
return config.Value
}
return openRestyConfigSnapshot{
snapshot := openRestyConfigSnapshot{
DefaultServerReturnStatus: getIntConfig(model.ConfigKeyOpenRestyDefaultServerReturnStatus, defaultOpenRestyReturnStatus),
WorkerProcesses: getStringConfig(model.ConfigKeyOpenRestyWorkerProcesses, "auto"),
WorkerConnections: getIntConfig(model.ConfigKeyOpenRestyWorkerConnections, defaultOpenRestyWorkerConns),
@@ -534,6 +534,19 @@ func buildOpenRestyConfigSnapshot(ctx context.Context) openRestyConfigSnapshot {
CacheUseStale: getStringConfig(model.ConfigKeyOpenRestyCacheUseStale, "error timeout updating http_500 http_502 http_503 http_504"),
MainConfigTemplate: getStringConfig(model.ConfigKeyOpenRestyMainConfigTemplate, model.DefaultOpenRestyMainConfigTemplate),
}
snapshot.CachePath = normalizeProxyCachePathForSnapshot(snapshot.CacheEnabled, snapshot.CachePath)
return snapshot
}
func normalizeProxyCachePathForSnapshot(cacheEnabled bool, cachePath string) string {
if !cacheEnabled {
return strings.TrimSpace(cachePath)
}
trimmed := strings.TrimSpace(cachePath)
if trimmed == "" || strings.HasPrefix(trimmed, "/var/") {
return openrestyrender.ProxyCachePathPlaceholder
}
return trimmed
}
func buildCertificateSupportFiles(ctx context.Context, routes []snapshotRoute) ([]SupportFile, error) {