fix(agent): write nginx pid and temp dirs under data_dir for non-root runtime

OpenResty running as openflare can no longer write pid or client/proxy temp
paths under the OpenResty install prefix. Templates and apply-time rendering
now use __OPENFLARE_PID_PATH__ and __OPENFLARE_NGINX_CACHE_DIR__ under
data_dir/var/run and data_dir/var/cache/nginx, with legacy pid path patched
at apply. Consolidate runtimeuser path helpers into the main package file so
IDEs resolve references across build tags.
This commit is contained in:
ryan
2026-06-21 14:40:10 +08:00
parent 9d56f02e64
commit 895dec208f
8 changed files with 169 additions and 97 deletions
+82 -1
View File
@@ -79,7 +79,7 @@ func EnsureProcessUser() error {
slog.Warn("agent is not running as runtime user", "expected", Name, "euid", os.Geteuid())
return nil
}
if dropErr := dropTo(account); dropErr != nil {
if dropErr := dropToImpl(account); dropErr != nil {
return dropErr
}
slog.Info("agent dropped privileges to runtime user", "user", Name, "uid", account.UID)
@@ -108,4 +108,85 @@ func EnsurePathOwnership(root string, dirPerm os.FileMode, filePerm os.FileMode)
return lookupErr
}
return applyOwnershipAndModes(root, account, dirPerm, filePerm)
}
var dropToImpl = func(account *Account) error {
return fmt.Errorf("drop to runtime user %s is not supported on this platform", account.Name)
}
func ensureWorldTraversablePath(targetDir string) error {
const maxDepth = 12
current := filepath.Clean(strings.TrimSpace(targetDir))
if current == "" || current == "." {
return nil
}
for depth := 0; depth < maxDepth; depth++ {
if err := os.Chmod(current, DefaultDirPerm); err != nil { //nolint:gosec // parent dirs must be traversable by the runtime user
if os.IsNotExist(err) || os.IsPermission(err) {
break
}
return fmt.Errorf("chmod %s: %w", current, err)
}
parent := filepath.Dir(current)
if parent == current {
break
}
current = parent
}
return nil
}
func applyOwnershipAndModes(root string, account *Account, dirPerm os.FileMode, filePerm os.FileMode) error {
return filepath.WalkDir(root, func(path string, entry os.DirEntry, walkErr error) error {
if walkErr != nil {
return walkErr
}
info, err := entry.Info()
if err != nil {
return err
}
if os.Geteuid() == 0 {
if chownErr := os.Chown(path, account.UID, account.GID); chownErr != nil && !os.IsNotExist(chownErr) { //nolint:gosec // path is under managed root walk
return fmt.Errorf("chown %s: %w", path, chownErr)
}
}
if entry.IsDir() {
if chmodErr := os.Chmod(path, dirPerm); chmodErr != nil && !os.IsNotExist(chmodErr) { //nolint:gosec // path is under managed root walk
return fmt.Errorf("chmod dir %s: %w", path, chmodErr)
}
return nil
}
if !info.Mode().IsRegular() {
return nil
}
if chmodErr := os.Chmod(path, filePerm); chmodErr != nil && !os.IsNotExist(chmodErr) { //nolint:gosec // path is under managed root walk
return fmt.Errorf("chmod file %s: %w", path, chmodErr)
}
return nil
})
}
func ensureModesOnly(root string, dirPerm os.FileMode, filePerm os.FileMode) error {
return filepath.WalkDir(root, func(path string, entry os.DirEntry, walkErr error) error {
if walkErr != nil {
return walkErr
}
info, err := entry.Info()
if err != nil {
return err
}
if entry.IsDir() {
if chmodErr := os.Chmod(path, dirPerm); chmodErr != nil && !os.IsNotExist(chmodErr) { //nolint:gosec // path is under managed root walk
return fmt.Errorf("chmod dir %s: %w", path, chmodErr)
}
return nil
}
if !info.Mode().IsRegular() {
return nil
}
if chmodErr := os.Chmod(path, filePerm); chmodErr != nil && !os.IsNotExist(chmodErr) { //nolint:gosec // path is under managed root walk
return fmt.Errorf("chmod file %s: %w", path, chmodErr)
}
return nil
})
}