Files
OpenFlare/internal/apps/agent/nginx/runtime_access.go
T
ryan aa4faddade 补齐 131 个 .go 文件的 SPDX license 头(repo 自带 make license 约定,早于约定新增的文件含 2 个生产文件;纯注释插入零行为影响),make license-check 转绿。go mod tidy -diff 确认干净。
Result: {"status":"keep","total_issues":8,"golint_canonicalheader":0,"golint_errname":0,"golint_errorlint":1,"golint_exhaustive":0,"golint_forcetypeassert":0,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":0,"golint_recvcheck":1,"golint_usestdlibvars":0,"golint_wastedassign":0,"golint_total":8,"golint_test_testifylint":0,"golint_test_thelper":0,"golint_test_usetesting":0,"golint_test_total":0,"golint_vetx_total":0,"eslint_problems":0,"eslint_errors":0,"eslint_warnings":0,"tsc_errors":0,"vitest_failed":0,"vitest_total":116,"measure_s":81}
2026-08-16 20:09:24 +08:00

33 lines
1.1 KiB
Go

// Copyright 2026 Arctel.net
// SPDX-License-Identifier: Apache-2.0
package nginx
import (
"github.com/Rain-kl/Wavelet/internal/apps/agent/runtimeuser"
)
// OpenFlareRuntimeUser is the shared OS account for the agent process and
// OpenResty worker processes.
const OpenFlareRuntimeUser = runtimeuser.Name
// OpenRestyWorkerUser is an alias kept for internal call sites.
const OpenRestyWorkerUser = runtimeuser.Name
// EnsureWorldTraversablePath makes targetDir and its ancestors world-traversable.
func EnsureWorldTraversablePath(targetDir string) error {
return runtimeuser.EnsurePathOwnership(targetDir, nginxDirPerm, nginxConfigFilePerm)
}
// EnsureWorkerReadableTree normalizes ownership and modes under root for the
// shared runtime user.
func EnsureWorkerReadableTree(rootDir string) error {
return runtimeuser.EnsurePathOwnership(rootDir, nginxDirPerm, nginxConfigFilePerm)
}
// EnsureWorkerReadAccess makes agent-managed runtime paths accessible to the
// shared runtime user.
func (m *Manager) EnsureWorkerReadAccess() error {
return m.ensureOpenRestyWorkerReadAccess()
}