mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-09-29 22:06:38 +08:00
895dec208f
OpenResty running as openflare can no longer write pid or client/proxy temp paths under the OpenResty install prefix. Templates and apply-time rendering now use __OPENFLARE_PID_PATH__ and __OPENFLARE_NGINX_CACHE_DIR__ under data_dir/var/run and data_dir/var/cache/nginx, with legacy pid path patched at apply. Consolidate runtimeuser path helpers into the main package file so IDEs resolve references across build tags.
29 lines
1.0 KiB
Go
29 lines
1.0 KiB
Go
package nginx
|
|
|
|
import (
|
|
"github.com/Rain-kl/Wavelet/internal/apps/agent/runtimeuser"
|
|
)
|
|
|
|
// OpenFlareRuntimeUser is the shared OS account for the agent process and
|
|
// OpenResty worker processes.
|
|
const OpenFlareRuntimeUser = runtimeuser.Name
|
|
|
|
// OpenRestyWorkerUser is an alias kept for internal call sites.
|
|
const OpenRestyWorkerUser = runtimeuser.Name
|
|
|
|
// EnsureWorldTraversablePath makes targetDir and its ancestors world-traversable.
|
|
func EnsureWorldTraversablePath(targetDir string) error {
|
|
return runtimeuser.EnsurePathOwnership(targetDir, nginxDirPerm, nginxConfigFilePerm)
|
|
}
|
|
|
|
// EnsureWorkerReadableTree normalizes ownership and modes under root for the
|
|
// shared runtime user.
|
|
func EnsureWorkerReadableTree(rootDir string) error {
|
|
return runtimeuser.EnsurePathOwnership(rootDir, nginxDirPerm, nginxConfigFilePerm)
|
|
}
|
|
|
|
// EnsureWorkerReadAccess makes agent-managed runtime paths accessible to the
|
|
// shared runtime user.
|
|
func (m *Manager) EnsureWorkerReadAccess() error {
|
|
return m.ensureOpenRestyWorkerReadAccess()
|
|
} |