fix(config): load config_secrets.json on hosts without os.geteuid (#590)

ensure_shared_group_ownership() - the chgrp self-heal ConfigManager runs
before reading config_secrets.json (#416) - looked up os.geteuid
unguarded. That name does not exist on Windows, and the AttributeError
is not an OSError, so it escaped the helper's best-effort handling and
every except clause in load_config(). Any Windows checkout with a
config/config_secrets.json got a ConfigError from every config load and
could not import web_interface.app.

That is what made test_update_all_plugins.py error at setup: its client
fixture imports web_interface.app. It was not state leaked between test
files - the trigger is whether the checkout has a secrets file.

Return early when os.geteuid or os.chown is missing. No change on POSIX.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-16 17:12:18 -04:00
committed by GitHub
co-authored by Claude Opus 5
parent f9b3d6ae52
commit 2082665252
4 changed files with 105 additions and 6 deletions
+10
View File
@@ -186,7 +186,17 @@ def ensure_shared_group_ownership(path: Path) -> None:
is group-readable, but without this the group is root's, not the web
user's. Silently does nothing if not running as root or on any error —
this is a hardening step, not a required one.
``os.geteuid``/``os.chown`` only exist on POSIX. On Windows there is no
root and no shared group to move the file to, so the whole step is moot —
but looking the names up unguarded raises ``AttributeError``, which is not
an ``OSError`` and so escapes every caller's error handling. That took
``ConfigManager.load_config()`` down on any Windows checkout that has a
``config/config_secrets.json``, i.e. every developer machine that has ever
run the app, and with it the import of ``web_interface.app``.
"""
if not hasattr(os, 'geteuid') or not hasattr(os, 'chown'):
return
if os.geteuid() != 0:
return
gid = get_shared_group_gid()