mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-05 07:26:36 +08:00
fix(agent): write nginx pid and temp dirs under data_dir for non-root runtime
OpenResty running as openflare can no longer write pid or client/proxy temp paths under the OpenResty install prefix. Templates and apply-time rendering now use __OPENFLARE_PID_PATH__ and __OPENFLARE_NGINX_CACHE_DIR__ under data_dir/var/run and data_dir/var/cache/nginx, with legacy pid path patched at apply. Consolidate runtimeuser path helpers into the main package file so IDEs resolve references across build tags.
This commit is contained in:
@@ -188,9 +188,9 @@ const (
|
||||
)
|
||||
|
||||
const safeDefaultFallbackMainConfig = `# This file is generated by OpenFlare safe default fallback.
|
||||
user ` + OpenFlareRuntimeUser + `;
|
||||
user ` + runtimeuser.Name + `;
|
||||
worker_processes auto;
|
||||
pid logs/nginx.pid;
|
||||
pid __OPENFLARE_PID_PATH__;
|
||||
|
||||
events {
|
||||
worker_connections 1024;
|
||||
@@ -199,6 +199,11 @@ events {
|
||||
http {
|
||||
default_type text/plain;
|
||||
server_tokens off;
|
||||
client_body_temp_path __OPENFLARE_NGINX_CACHE_DIR__/client_temp;
|
||||
proxy_temp_path __OPENFLARE_NGINX_CACHE_DIR__/proxy_temp;
|
||||
fastcgi_temp_path __OPENFLARE_NGINX_CACHE_DIR__/fastcgi_temp;
|
||||
uwsgi_temp_path __OPENFLARE_NGINX_CACHE_DIR__/uwsgi_temp;
|
||||
scgi_temp_path __OPENFLARE_NGINX_CACHE_DIR__/scgi_temp;
|
||||
|
||||
server {
|
||||
listen 80 default_server;
|
||||
@@ -294,6 +299,9 @@ func (m *Manager) ensureOpenRestyWorkerReadAccess() error {
|
||||
if m.AccessLogPath != "" {
|
||||
targets = append(targets, filepath.Dir(m.AccessLogPath))
|
||||
}
|
||||
if pidPath := m.pidRuntimePath(); pidPath != "" {
|
||||
targets = append(targets, filepath.Dir(pidPath))
|
||||
}
|
||||
seen := make(map[string]struct{}, len(targets))
|
||||
for _, target := range targets {
|
||||
cleaned := filepath.Clean(strings.TrimSpace(target))
|
||||
@@ -474,6 +482,9 @@ func (m *Manager) CurrentChecksum() (string, error) {
|
||||
errorLogPath := filepath.Join(filepath.Dir(accessLogPath), "error.log")
|
||||
normalizedMain = strings.ReplaceAll(normalizedMain, filepath.ToSlash(errorLogPath), openrestyrender.ErrorLogPlaceholder)
|
||||
}
|
||||
if pidPath := m.pidRuntimePath(); pidPath != "" {
|
||||
normalizedMain = strings.ReplaceAll(normalizedMain, filepath.ToSlash(pidPath), openrestyrender.PIDPathPlaceholder)
|
||||
}
|
||||
if luaDir := m.luaRuntimePath(); luaDir != "" {
|
||||
normalizedMain = strings.ReplaceAll(normalizedMain, luaDir, openrestyrender.LuaDirPlaceholder)
|
||||
}
|
||||
@@ -991,7 +1002,7 @@ func (m *Manager) writeSafeDefaultFallbackFiles() error {
|
||||
if err := os.WriteFile(m.RouteConfigPath, nil, nginxConfigFilePerm); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := os.WriteFile(m.MainConfigPath, []byte(m.safeDefaultFallbackMainConfig()), nginxConfigFilePerm); err != nil {
|
||||
if err := os.WriteFile(m.MainConfigPath, []byte(m.renderMainConfig(m.safeDefaultFallbackMainConfig())), nginxConfigFilePerm); err != nil {
|
||||
return err
|
||||
}
|
||||
return nil
|
||||
@@ -1228,6 +1239,30 @@ func (m *Manager) renderMainConfig(content string) string {
|
||||
errorLogPath := filepath.Join(filepath.Dir(accessLogPath), "error.log")
|
||||
rendered = strings.ReplaceAll(rendered, openrestyrender.ErrorLogPlaceholder, filepath.ToSlash(errorLogPath))
|
||||
}
|
||||
if pidPath := m.pidRuntimePath(); pidPath != "" {
|
||||
slashPIDPath := filepath.ToSlash(pidPath)
|
||||
rendered = strings.ReplaceAll(rendered, openrestyrender.PIDPathPlaceholder, slashPIDPath)
|
||||
rendered = strings.ReplaceAll(rendered, "pid logs/nginx.pid;", "pid "+slashPIDPath+";")
|
||||
if err := os.MkdirAll(filepath.Dir(pidPath), nginxDirPerm); err != nil {
|
||||
slog.Warn("ensure nginx pid directory failed", "path", filepath.Dir(pidPath), "error", err)
|
||||
}
|
||||
}
|
||||
if cacheDir := m.nginxCacheRuntimeDir(); cacheDir != "" {
|
||||
slashCacheDir := filepath.ToSlash(cacheDir)
|
||||
rendered = strings.ReplaceAll(rendered, openrestyrender.NginxCacheDirPlaceholder, slashCacheDir)
|
||||
if !strings.Contains(rendered, "client_body_temp_path") {
|
||||
writablePaths := fmt.Sprintf(
|
||||
" client_body_temp_path %s/client_temp;\n proxy_temp_path %s/proxy_temp;\n fastcgi_temp_path %s/fastcgi_temp;\n uwsgi_temp_path %s/uwsgi_temp;\n scgi_temp_path %s/scgi_temp;\n",
|
||||
slashCacheDir, slashCacheDir, slashCacheDir, slashCacheDir, slashCacheDir,
|
||||
)
|
||||
rendered = strings.Replace(rendered, "http {", "http {\n"+writablePaths, 1)
|
||||
}
|
||||
for _, subDir := range []string{"client_temp", "proxy_temp", "fastcgi_temp", "uwsgi_temp", "scgi_temp"} {
|
||||
if err := os.MkdirAll(filepath.Join(cacheDir, subDir), nginxDirPerm); err != nil {
|
||||
slog.Warn("ensure nginx cache directory failed", "path", filepath.Join(cacheDir, subDir), "error", err)
|
||||
}
|
||||
}
|
||||
}
|
||||
if luaDir := m.luaRuntimePath(); luaDir != "" {
|
||||
rendered = strings.ReplaceAll(rendered, openrestyrender.LuaDirPlaceholder, luaDir)
|
||||
}
|
||||
@@ -1339,6 +1374,30 @@ func (m *Manager) accessLogRuntimePath() string {
|
||||
return filepath.ToSlash(strings.TrimSpace(m.AccessLogPath))
|
||||
}
|
||||
|
||||
func (m *Manager) varRuntimeDir() string {
|
||||
if accessLogPath := strings.TrimSpace(m.AccessLogPath); accessLogPath != "" {
|
||||
return filepath.Dir(filepath.Dir(filepath.Dir(accessLogPath)))
|
||||
}
|
||||
if mainConfigPath := strings.TrimSpace(m.MainConfigPath); mainConfigPath != "" {
|
||||
return filepath.Clean(filepath.Join(filepath.Dir(mainConfigPath), "..", ".."))
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (m *Manager) pidRuntimePath() string {
|
||||
if varRoot := m.varRuntimeDir(); varRoot != "" {
|
||||
return filepath.ToSlash(filepath.Join(varRoot, "run", "nginx.pid"))
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (m *Manager) nginxCacheRuntimeDir() string {
|
||||
if varRoot := m.varRuntimeDir(); varRoot != "" {
|
||||
return filepath.ToSlash(filepath.Join(varRoot, "cache", "nginx"))
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (m *Manager) luaRuntimePath() string {
|
||||
if strings.TrimSpace(m.NginxLuaDir) == "" {
|
||||
return ""
|
||||
|
||||
@@ -1,17 +1,15 @@
|
||||
package nginx
|
||||
|
||||
import (
|
||||
openrestyrender "github.com/Rain-kl/Wavelet/pkg/render/openresty"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/agent/runtimeuser"
|
||||
)
|
||||
|
||||
// OpenFlareRuntimeUser is the shared OS account for the agent process and
|
||||
// OpenResty worker processes.
|
||||
const OpenFlareRuntimeUser = openrestyrender.OpenFlareRuntimeUser
|
||||
const OpenFlareRuntimeUser = runtimeuser.Name
|
||||
|
||||
// OpenRestyWorkerUser is an alias kept for internal call sites.
|
||||
const OpenRestyWorkerUser = OpenFlareRuntimeUser
|
||||
const OpenRestyWorkerUser = runtimeuser.Name
|
||||
|
||||
// EnsureWorldTraversablePath makes targetDir and its ancestors world-traversable.
|
||||
func EnsureWorldTraversablePath(targetDir string) error {
|
||||
|
||||
Reference in New Issue
Block a user