mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-04 14:25:08 +00:00
* fix(errors): record the exception's own stack trace record_error() called traceback.format_exc(), which only sees an exception while its except block is running. plugin_executor records exceptions caught on a worker thread after that block has ended, so every trace on /errors read "NoneType: None". The trace is now built from the exception's __traceback__. The executor's log call had the same problem with exc_info=True and now passes the exception. record_error() also merged LEDMatrixError context into the caller's dict in place; it now works on a copy. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(wifi): point at configure_wifi_permissions.sh instead of a sudoers list The module docstring told users to grant NOPASSWD sudo on iptables and ip. configure_wifi_permissions.sh refuses those grants on purpose: a wildcard rule for either runs an arbitrary program as root. Point at the script and say why it leaves them out. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(wifi): disconnect finds the saved profile by SSID disconnect_from_network() asked `nmcli -f NAME,802-11-wireless.ssid connection show` for the profile to take down, but nmcli rejects that column for `connection show`, so the lookup always failed and only the device was disconnected. The per-profile lookup _connect_nmcli() already used is now _find_profile_for_ssid(), and both callers share it. It also splits terse output on the last colon and unescapes "\:", so a profile name containing a colon is found. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(wifi): write wifi_config.json atomically and report a failed save _save_config() opened the file for writing in place and swallowed any error, so a wifi_config.json left owned by root made the web toggle for auto-enabling AP mode report success while nothing was saved, and a crash mid-write could truncate the file. It now uses atomic_write_json, which also keeps the file's owner and shared group when root saves it, and returns False on failure. POST /wifi/ap/auto-enable answers 500 in that case. The file is now written with indent=4, like the other config files. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(fonts): resolve plugin:// fonts in the plugin's own directory FontManager looked for a plugin's bundled fonts under Path("plugins") / plugin_id: relative to the process cwd, and not the default install directory (plugin-repos/), so a manifest's plugin:// fonts never loaded. register_plugin_fonts() takes an optional plugin_dir, and PluginManager passes the directory it loaded the plugin from. Callers that omit it get a lookup in the configured plugin_system.plugins_directory, then plugins/, resolved against the install root. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(api-helper): cache responses for the requested cache_ttl APIHelper.get(cache_ttl=...) and set_cache(ttl=...) dropped the ttl on the claim that CacheManager does not support one, but CacheManager.set() takes a ttl, stores it with the entry, and both cache tiers honour it over a reader's max_age. Without it every response expired after the 300-second default read age, whatever the plugin asked for. The ttl is now passed through, and the cache read passes cache_ttl as max_age for entries written without one. The class docstring describes what the helper actually does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(style): one scale range for the schema, element_scale and LogoHelper The generated Scale field allowed 0.1 to 10, element_style's reader capped at 10 with no floor, and LogoHelper accepted 0.05 to 8 and reset anything else to 1.0. A logo scale of 9, which the form accepts, drew at the shipped size. MIN_ELEMENT_SCALE / MAX_ELEMENT_SCALE (0.1, 10.0) in src.element_style are now the schema bounds and the clamp every reader applies through coerce_scale(): a positive number outside the range is clamped, and anything that is not a finite positive number means the default. That also stops element_scale() passing NaN through, since min(nan, 10.0) is nan. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(logos): placeholder lands at the requested path; empty logos list download_missing_logo() wrote its fallback placeholder to <normalize_abbreviation(abbr)>.png in the logo directory rather than to the logo_path the caller passed, so it could return True while nothing existed where the plugin looks (e.g. "TA&M.png" vs "TAANDM.png"). create_placeholder_logo() takes an optional filepath, and download_missing_logo passes the requested one. download_missing_logo_for_team() only caught KeyError, so a team whose "logos" list is empty raised IndexError; it now treats KeyError, IndexError and TypeError as "no logo URL". The placeholder is drawn with PLACEHOLDER_SIZE / PLACEHOLDER_BG, the constants is_placeholder_logo() recognises it by, instead of repeated literals. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(fonts): resolve bundled font paths against the install root TextHelper's default font_dir, the logo placeholder's font and FontManager's font_overrides.json were all relative to the process cwd, so a process started anywhere but the install root (the plugin safety harness, a manual run, a unit without WorkingDirectory) drew with PIL's default face and read no overrides. They now go through font_layout.resolve_asset_path; the overrides file sits in the install root's config/. The resolver docstrings described an order the code does not follow: resolve_asset_path never consults the cwd, and sports_shared's _resolve_font_path tries the cwd first. Both docstrings now say what the code does, and _resolve_font_path calls resolve_asset_path instead of probing FontManager for it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(sync): the web UI reads the sync status file the display writes sync_manager writes its status to tempfile.gettempdir(), but GET /api/v3/sync/status read a hardcoded /tmp/led_matrix_sync_status.json and defaulted the port to a literal 5765. Wherever TMPDIR is set (or on any non-/tmp host) the page only ever showed "starting". The endpoint now uses sync_manager.STATUS_FILE and SYNC_PORT. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(http): the rankings resolver sends the project's User-Agent DynamicTeamResolver fetched ESPN rankings with a bare requests.get, so it sent python-requests' default User-Agent, which ESPN rejects; the AP_TOP_N favourites then resolved to nothing. It now sends DEFAULT_HTTP_HEADERS. BaseOddsManager carried its own copy of the User-Agent string and now uses the same shared headers (which also adds Accept-Language). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(backup): record the core release and read the configured plugin dir The manifest's ledmatrix_version came from a VERSION file that does not exist, then from .git/HEAD: a 12-character sha, or "ref: refs/he" when the branch's ref was packed. It is now src.__version__. list_installed_plugins() scanned a hardcoded plugin-repos/, so on an install whose plugin_system.plugins_directory points elsewhere, plugins missing from plugin_state.json were left out of the backup. It now reads the configured directory from config/config.json, defaulting to plugin-repos. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(startup): report a missing display section once A config without a display section produced three errors for the one problem ("Missing required configuration key: display", "Display configuration is missing or empty" and "Display configuration is missing"), and an empty one produced two. _validate_config now reports it once, as a missing key or an empty section, and _validate_display_config leaves it to that. The module docstring said the validator fails fast; nothing in the display service calls raise_on_errors(), so it now says the errors are reported and startup continues. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(wifi): share the copied blocks and name the AP constants - _parse_nmcli_wifi_list() is the one parser behind _scan_nmcli and _scan_nmcli_cached. - _verify_connected(), _wait_for_device_idle(), _failsafe_ap() and _mark_forced() replace blocks that were pasted two or three times in the connect and enable-AP paths. The device-idle wait now checks before its first one-second sleep instead of after it. - _check_command() calls _find_command_path() instead of repeating it. - AP_IP, PORTAL_PORT, AP_PROFILE_NAME and AP_PROFILE_NAMES name values that were spelled out 14, 12, 8 and 2 times; the two deletion loops now walk the same tuple. The iwconfig status path compares the AP address exactly: startswith() also skipped 192.168.4.10-19. - Dropped a second WIFI.SIGNAL query that repeated the first, a no-op "if ssid: continue", the try/except around _connect_wpa_supplicant's constant return, and a second save of a scan scan_networks already saves. - _ensure_wifi_radio_enabled's docstring says it returns True when the radio state cannot be read at all. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(config): drop dead branches and history comments in ConfigManager - The module docstring pointed plugin authors at update_plugin_config(), which does not exist; it now names save_config_atomic() and save_raw_file_content(). - load_config's FileNotFoundError handler tested the message for "config_secrets.json", but a missing secrets file is handled where it is read, so only config.json reaches it; the check is gone. - save_raw_file_content's `file_type == "main" or "secrets"` guard was always true (anything else raised earlier). - get_raw_file_content('secrets') already returns {} for a missing file, so the os.path.exists() in front of two calls to it is gone. - Comments that narrated earlier behaviour are rewritten as what the code does now. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(background-data): present-tense comments, drop unused API - Comments that told the history of each fix (what "used to" happen, "the old per-delivery release") now state the invariant the code keeps. - get_statistics() no longer reports a constant 'queue_size': 0, and the uncalled clear_completed_requests() is gone (_cleanup_completed_requests does that job on every completion). Neither is referenced in core, the web UI or the plugin monorepo. shutdown_background_service() has no production caller either, but it is the only way to tear down the get_background_service() singleton, which the tests rely on, so it stays. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(odds): drop the unread cache_ttl and merge the odds_data branches BaseOddsManager loaded base_odds_manager.cache_ttl from config and never used it: cached odds live for the update interval (get_odds' ttl=interval). No core or monorepo code reads the attribute, so it is gone along with its log line. The two consecutive `if odds_data:` blocks are one. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(backup): one table for the single-file sections config, secrets, wifi and ytm_auth were each spelled out in create, preview, validate and restore. _SINGLE_FILE_SECTIONS lists them once, with the RestoreOptions flag that restores each, and all four walk it. Restore error messages keep their wording ("Failed to restore <file name>"). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(fonts): drop FontManager's write-only state and duplicate logs - fonts_config, font_metadata and font_dependencies were written and never read; the performance_stats keys font_load_times, render_times, total_renders and the per-call "resolve" timings (_record_performance_metric) likewise. get_performance_stats() reads only the counters that remain. Nothing in core or the plugin monorepo references any of them. - A failed BDF load was logged twice, by _load_bdf_font and again by get_font; get_font's line is the one kept. - Removed "NEW:" and commented-out cozette entries, the "Copy font to assets/fonts" comment on code that copies nothing, and local imports of names the module already imports. The deprecated add_font() now resolves assets/fonts against the install root. The @deprecated methods stay. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(text-helper): cache loaded fonts; drop the pre-textlength fallback TextHelper declared _font_cache, cleared it and reported its size, but never stored anything in it. load_fonts() now keeps each (file, size) it loads there, so clear_font_cache() and get_font_cache_stats() mean what they say and repeated load_fonts() calls reuse the fonts. get_text_width() no longer catches AttributeError for Pillow releases without ImageDraw.textlength; requirements.txt pins Pillow>=12.2. The class docstring describes what the helper does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(common): fix wrong docstrings in api_helper, permission_utils, snapshot_policy - permission_utils called 0o2775 "sticky bit"; the 2 is setgid, which is what makes new files take the directory's group. - snapshot_policy pointed at web_interface/blueprints/api_v3.py, which is a package now; the health check is in api_v3/misc.py. - APIHelper.clear_cache() lost a history note and a fallback to a clear() method that neither CacheManager nor the testing MockCacheManager has. The session headers are built from DEFAULT_HTTP_HEADERS instead of a copy of them, and the module docstring says what the module offers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(sports): present-tense comments in the shared scoreboard renderers - sports_scroll and sports_game_renderer comments that referred to "this PR", "the old flat 128px card" or what the renderer "previously" did now describe the current behaviour and its reason. - The block explaining why non-finite settings are rejected sat above _score_reserve_width; it describes _center_gap_width and now lives in it. - unshare_element_fonts wrapped its import of font_layout.load_truetype in an `except ImportError` that cannot fire inside core; the import stays at call time so tests can spy on the pinned loader. - sports_card docstrings that told the history of a fix say what the code does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(sports-shared): drop dead code, name the ESPN limit - _get_weeks_data asked for limit=1000, which fetch_espn_scoreboard clamps to ESPN_MAX_LIMIT anyway; it now names that constant. Its unused `immediate_events = []` is gone. - _get_season_schedule_dates() returned ("", "") and has no caller in core or the plugin monorepo. - _should_log keeps its warning_type parameter (part of the inherited signature, though nothing in core or the monorepo calls it) and its docstring says the cooldown is shared across types. - An unused ImageFont import is gone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(sync): one follower-mode switch, shared panel defaults - The class docstring said the leader sends PNG frames. Frames go over UDP as raw RGB; PNG is only the Vegas scroll image sent over TCP. It now describes both paths. - _enter_follower_mode() replaces the two copies of "note the leader, switch from standalone to follower, log, write status" in the frame and scroll-position handlers. - The rows/cols fallbacks use DEFAULT_ROWS / DEFAULT_COLS from src.display_geometry, as chain_length already did. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(style): drop _layout_axis, name the layout group title - ElementStyleResolver._layout_axis() had no caller in core or the plugin monorepo. - _element_block_from_spec checked spec['size'] was a dict again after size_spec already had; it reads size_spec. - The "Layout Offsets" title written into three generated schema blocks is _LAYOUT_TITLE. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(logo-helper): say what the placeholder draws; name the 1.5 box factor - _create_placeholder_logo's docstring said it draws the team abbreviation; it draws an outlined grey box and nothing else. The docstring says so, and the "in a real implementation you'd want text" comments are gone. - The 1.5 x panel default logo box, written out six times, is DEFAULT_LOGO_BOX_FACTOR. - ImageDraw is imported with Image at the top of the module. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(logos): drop dead code and a duplicate regex in logo_downloader - _SAFE_LEAGUE_CODE_RE was the same pattern as _SAFE_LEAGUE_RE; both checks use the one. - get_logo_filename_variations reassigned the TA&M case to the list it already had; the function returns the two names directly. - _get_team_name_variations() had no caller in core or the plugin monorepo. - fetch_single_team's docstring was copied from fetch_teams_data; a log message read "for{team_id}". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor: drop the Pillow<9.1 resample shim and a catch-and-reraise - adaptive_images fell back to Image.LANCZOS/NEAREST for Pillow < 9.1; requirements.txt pins Pillow>=12.2. RESAMPLE_LANCZOS and RESAMPLE_NEAREST keep their names (src.common re-exports them). - CacheManager.save_cache caught CacheError only to re-raise it; the disk write is now called directly, with the same result. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test(api-helper): stop the real CacheManager's cleanup thread The cache-lifetime tests built a CacheManager and left its cleanup thread's class-wide claim on the directory in place, which broke test_cache_cleanup_thread_ownership when it ran later in the session. The fixture now stops the thread on teardown. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(changelog): core-common Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
500 lines
19 KiB
Python
500 lines
19 KiB
Python
"""
|
|
Permission Utilities
|
|
|
|
Centralized utility functions for managing file and directory permissions
|
|
across the LEDMatrix codebase. Ensures consistent permission handling for
|
|
files that need to be accessible by both root service and web user.
|
|
"""
|
|
|
|
import os
|
|
import logging
|
|
import re
|
|
import shutil as _shutil
|
|
import subprocess
|
|
import sys
|
|
from pathlib import Path
|
|
from typing import Optional
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
# Matches the credentials portion of a "scheme://user:pass@host" URL, so pip's
|
|
# own error output can be logged/displayed without echoing back a private
|
|
# index URL's embedded basic-auth secret verbatim (e.g. from a
|
|
# requirements.txt --index-url line or the PIP_INDEX_URL env var).
|
|
_URL_CREDENTIALS_RE = re.compile(r'://[^/\s@:]+:[^/\s@]+@')
|
|
|
|
|
|
def _redact_url_credentials(text: Optional[str]) -> str:
|
|
"""Replace embedded user:pass@ URL credentials in text with a placeholder.
|
|
|
|
Safe to call on any subprocess output destined for logs: it only ever
|
|
shortens/replaces the credential substring, never changes the presence
|
|
or absence of the specific fixed phrases callers check for
|
|
(e.g. "a password is required"), so it can't affect control flow.
|
|
"""
|
|
if not text:
|
|
return text or ""
|
|
return _URL_CREDENTIALS_RE.sub('://***:***@', text)
|
|
|
|
# System directories that should never have their permissions modified
|
|
# These directories have special system-level permissions that must be preserved
|
|
PROTECTED_SYSTEM_DIRECTORIES = { # nosec B108 - these are checked to PREVENT permission changes, not to use as temp paths
|
|
'/tmp',
|
|
'/var/tmp',
|
|
'/dev',
|
|
'/proc',
|
|
'/sys',
|
|
'/run',
|
|
'/var/run',
|
|
'/etc',
|
|
'/boot',
|
|
'/var',
|
|
'/usr',
|
|
'/lib',
|
|
'/lib64',
|
|
'/bin',
|
|
'/sbin',
|
|
}
|
|
|
|
|
|
def ensure_directory_permissions(path: Path, mode: int = 0o775) -> None:
|
|
"""
|
|
Create directory and set permissions.
|
|
|
|
If the directory already exists and we cannot change its permissions,
|
|
we check if it's usable (readable/writable). If so, we continue without
|
|
raising an exception. This allows the system to work even when running
|
|
as a non-root user who cannot change permissions on existing directories.
|
|
|
|
Protected system directories (like /tmp, /etc, /var) are never modified
|
|
to prevent breaking system functionality.
|
|
|
|
Args:
|
|
path: Directory path to create/ensure
|
|
mode: Permission mode (default: 0o775 for group-writable directories)
|
|
|
|
Raises:
|
|
OSError: If directory creation fails or directory exists but is not usable
|
|
"""
|
|
try:
|
|
# Never modify permissions on system directories
|
|
path_str = str(path.resolve() if path.is_absolute() else path)
|
|
if path_str in PROTECTED_SYSTEM_DIRECTORIES:
|
|
logger.debug(f"Skipping permission modification on protected system directory: {path_str}")
|
|
# Verify the directory is usable
|
|
if path.exists() and os.access(path, os.R_OK | os.W_OK):
|
|
return
|
|
elif path.exists():
|
|
logger.warning(f"Protected system directory {path_str} exists but is not writable")
|
|
return
|
|
else:
|
|
raise OSError(f"Protected system directory {path_str} does not exist")
|
|
|
|
# Create directory if it doesn't exist
|
|
path.mkdir(parents=True, exist_ok=True)
|
|
|
|
# Try to set permissions
|
|
try:
|
|
os.chmod(path, mode)
|
|
logger.debug(f"Set directory permissions {oct(mode)} on {path}")
|
|
except (OSError, PermissionError) as perm_error:
|
|
# If we can't set permissions, check if directory is usable
|
|
if path.exists():
|
|
# Check if directory is readable and writable
|
|
if os.access(path, os.R_OK | os.W_OK):
|
|
logger.warning(
|
|
f"Could not set permissions on {path} (may be owned by different user), "
|
|
f"but directory is usable (readable/writable). Continuing."
|
|
)
|
|
return
|
|
else:
|
|
# Directory exists but is not usable
|
|
logger.error(
|
|
f"Directory {path} exists but is not readable/writable. "
|
|
f"Permission change failed: {perm_error}"
|
|
)
|
|
raise OSError(
|
|
f"Directory {path} exists but is not usable: {perm_error}"
|
|
) from perm_error
|
|
else:
|
|
# Directory doesn't exist and we couldn't create it
|
|
raise
|
|
except OSError as e:
|
|
logger.error(f"Failed to ensure directory {path}: {e}")
|
|
raise
|
|
|
|
|
|
def ensure_file_permissions(path: Path, mode: int = 0o644) -> None:
|
|
"""
|
|
Set file permissions after creation.
|
|
|
|
Args:
|
|
path: File path to set permissions on
|
|
mode: Permission mode (default: 0o644 for readable files)
|
|
|
|
Raises:
|
|
OSError: If permission setting fails
|
|
"""
|
|
try:
|
|
if path.exists():
|
|
os.chmod(path, mode)
|
|
logger.debug(f"Set file permissions {oct(mode)} on {path}")
|
|
else:
|
|
logger.warning(f"File does not exist, cannot set permissions: {path}")
|
|
except OSError as e:
|
|
logger.error(f"Failed to set file permissions on {path}: {e}")
|
|
raise
|
|
|
|
|
|
_shared_group_gid_cache: Optional[int] = None
|
|
|
|
|
|
def get_shared_group_gid() -> Optional[int]:
|
|
"""
|
|
Return the gid that should own config/secrets files shared between the
|
|
root-run ``ledmatrix.service`` (main display) and the non-root user that
|
|
``ledmatrix-web.service`` runs as (see install_web_service.sh, which sets
|
|
``User=$SUDO_USER``).
|
|
|
|
Resolved once from the project root directory's current group (normally
|
|
the login user's group from the initial ``git clone``), since that user
|
|
is stable across reinstalls unlike any single file's ownership.
|
|
|
|
Returns:
|
|
The gid, or None if it cannot be determined.
|
|
"""
|
|
global _shared_group_gid_cache
|
|
if _shared_group_gid_cache is not None:
|
|
return _shared_group_gid_cache
|
|
try:
|
|
project_root = Path(__file__).resolve().parent.parent.parent
|
|
_shared_group_gid_cache = project_root.stat().st_gid
|
|
return _shared_group_gid_cache
|
|
except OSError:
|
|
return None
|
|
|
|
|
|
def ensure_shared_group_ownership(path: Path) -> None:
|
|
"""
|
|
Best-effort chgrp of ``path`` to the shared group (see
|
|
:func:`get_shared_group_gid`) when running as root.
|
|
|
|
Only root can change a file's group to one the calling process isn't a
|
|
member of, which is exactly the case that causes the web interface
|
|
(running as a non-root user) to get ``PermissionError`` reading files
|
|
the root-run display service just wrote with a 0o640/2775 mode: the mode
|
|
is group-readable, but without this the group is root's, not the web
|
|
user's. Silently does nothing if not running as root or on any error —
|
|
this is a hardening step, not a required one.
|
|
|
|
``os.geteuid``/``os.chown`` only exist on POSIX. On Windows there is no
|
|
root and no shared group to move the file to, so the whole step is moot —
|
|
but looking the names up unguarded raises ``AttributeError``, which is not
|
|
an ``OSError`` and so escapes every caller's error handling. That took
|
|
``ConfigManager.load_config()`` down on any Windows checkout that has a
|
|
``config/config_secrets.json``, i.e. every developer machine that has ever
|
|
run the app, and with it the import of ``web_interface.app``.
|
|
"""
|
|
if not hasattr(os, 'geteuid') or not hasattr(os, 'chown'):
|
|
return
|
|
if os.geteuid() != 0:
|
|
return
|
|
gid = get_shared_group_gid()
|
|
if gid is None:
|
|
return
|
|
try:
|
|
if path.exists() and path.stat().st_gid != gid:
|
|
os.chown(path, -1, gid)
|
|
logger.debug(f"Set shared group ownership (gid {gid}) on {path}")
|
|
except OSError as e:
|
|
logger.debug(f"Could not set shared group ownership on {path}: {e}")
|
|
|
|
|
|
def get_config_file_mode(file_path: Path) -> int:
|
|
"""
|
|
Return appropriate permission mode for config files.
|
|
|
|
Args:
|
|
file_path: Path to config file
|
|
|
|
Returns:
|
|
Permission mode: 0o640 for secrets files, 0o644 for regular config
|
|
"""
|
|
if 'secrets' in str(file_path):
|
|
return 0o640 # rw-r-----
|
|
else:
|
|
return 0o644 # rw-r--r--
|
|
|
|
|
|
def get_assets_file_mode() -> int:
|
|
"""
|
|
Return permission mode for asset files (logos, images, etc.).
|
|
|
|
Returns:
|
|
Permission mode: 0o664 (rw-rw-r--) for group-writable assets
|
|
"""
|
|
return 0o664 # rw-rw-r--
|
|
|
|
|
|
def get_assets_dir_mode() -> int:
|
|
"""
|
|
Return permission mode for asset directories.
|
|
|
|
Returns:
|
|
Permission mode: 0o2775 (rwxrwsr-x): group-writable, and setgid so
|
|
entries created in it take the directory's group
|
|
"""
|
|
return 0o2775 # rwxrwsr-x (setgid + group writable)
|
|
|
|
|
|
def get_config_dir_mode() -> int:
|
|
"""
|
|
Return permission mode for config directory.
|
|
|
|
Returns:
|
|
Permission mode: 0o2775 (rwxrwsr-x): group-writable, and setgid so
|
|
entries created in it take the directory's group
|
|
"""
|
|
return 0o2775 # rwxrwsr-x (setgid + group writable)
|
|
|
|
|
|
def get_plugin_file_mode() -> int:
|
|
"""
|
|
Return permission mode for plugin files.
|
|
|
|
Returns:
|
|
Permission mode: 0o664 (rw-rw-r--) for group-writable plugin files
|
|
"""
|
|
return 0o664 # rw-rw-r--
|
|
|
|
|
|
def get_plugin_dir_mode() -> int:
|
|
"""
|
|
Return permission mode for plugin directories.
|
|
|
|
Returns:
|
|
Permission mode: 0o2775 (rwxrwsr-x): group-writable, and setgid so
|
|
entries created in it take the directory's group
|
|
"""
|
|
return 0o2775 # rwxrwsr-x (setgid + group writable)
|
|
|
|
|
|
def get_cache_dir_mode() -> int:
|
|
"""
|
|
Return permission mode for cache directories.
|
|
|
|
Returns:
|
|
Permission mode: 0o2775 (rwxrwsr-x): group-writable, and setgid so
|
|
entries created in it take the directory's group
|
|
"""
|
|
return 0o2775 # rwxrwsr-x (setgid + group writable)
|
|
|
|
|
|
def sudo_remove_directory(path: Path, allowed_bases: Optional[list] = None) -> bool:
|
|
"""
|
|
Remove a directory using sudo as a last resort.
|
|
|
|
Used when normal removal fails due to root-owned files (e.g., __pycache__
|
|
directories created by the root ledmatrix service). Delegates to the
|
|
safe_plugin_rm.sh helper which validates the path is inside allowed
|
|
plugin directories.
|
|
|
|
Before invoking sudo, this function also validates that the resolved
|
|
path is a descendant of at least one allowed base directory.
|
|
|
|
Args:
|
|
path: Directory path to remove
|
|
allowed_bases: List of allowed parent directories. If None, defaults
|
|
to plugin-repos/ and plugins/ under the project root.
|
|
|
|
Returns:
|
|
True if removal succeeded, False otherwise
|
|
"""
|
|
# Determine project root (permission_utils.py is at src/common/)
|
|
project_root = Path(__file__).resolve().parent.parent.parent
|
|
|
|
if allowed_bases is None:
|
|
allowed_bases = [
|
|
project_root / "plugin-repos",
|
|
project_root / "plugins",
|
|
]
|
|
|
|
# Resolve the target path to prevent symlink/traversal tricks
|
|
try:
|
|
resolved = path.resolve()
|
|
except (OSError, ValueError) as e:
|
|
logger.error(f"Cannot resolve path {path}: {e}")
|
|
return False
|
|
|
|
# Validate the resolved path is a strict child of an allowed base
|
|
is_allowed = False
|
|
for base in allowed_bases:
|
|
try:
|
|
base_resolved = base.resolve()
|
|
if resolved != base_resolved and resolved.is_relative_to(base_resolved):
|
|
is_allowed = True
|
|
break
|
|
except (OSError, ValueError):
|
|
continue
|
|
|
|
if not is_allowed:
|
|
logger.error(
|
|
f"sudo_remove_directory DENIED: {resolved} is not inside "
|
|
f"allowed bases {[str(b) for b in allowed_bases]}"
|
|
)
|
|
return False
|
|
|
|
# Use the safe_plugin_rm.sh helper which does its own validation
|
|
helper_script = project_root / "scripts" / "fix_perms" / "safe_plugin_rm.sh"
|
|
if not helper_script.exists():
|
|
logger.error(f"Safe removal helper not found: {helper_script}")
|
|
return False
|
|
|
|
bash_path = _shutil.which('bash') or '/bin/bash'
|
|
|
|
try:
|
|
result = subprocess.run(
|
|
['sudo', '-n', bash_path, str(helper_script), str(resolved)],
|
|
capture_output=True,
|
|
text=True,
|
|
timeout=30
|
|
)
|
|
if result.returncode == 0 and not resolved.exists():
|
|
logger.info(f"Successfully removed {path} via sudo helper")
|
|
return True
|
|
else:
|
|
stderr = result.stderr.strip()
|
|
logger.error(f"sudo helper failed for {path}: {stderr}")
|
|
return False
|
|
except subprocess.TimeoutExpired:
|
|
logger.error(f"sudo helper timed out for {path}")
|
|
return False
|
|
except FileNotFoundError:
|
|
logger.error("sudo command not found on system")
|
|
return False
|
|
except Exception as e:
|
|
logger.error(f"Unexpected error during sudo helper for {path}: {e}")
|
|
return False
|
|
|
|
|
|
#: What sudo prints when it refuses a command line outright (not in sudoers for
|
|
#: that exact argv, or it wants a password). Only then is another bash path
|
|
#: worth trying: after pip itself ran, a retry just repeats the failure. The
|
|
#: automatic update's health check keeps its own copy of this list
|
|
#: (scripts/utils/auto_update_verify.py runs without importing src/).
|
|
SUDO_REFUSAL_PHRASES = ("a password is required", "is not allowed to run", "no tty present")
|
|
|
|
|
|
def install_requirements_file(req_file: Path, timeout: int = 300) -> subprocess.CompletedProcess:
|
|
"""
|
|
Install a requirements.txt file for a plugin (or the project itself).
|
|
|
|
Prefers the vetted sudo wrapper (scripts/fix_perms/safe_pip_install.sh) so
|
|
packages end up visible to root-run ledmatrix.service, not just to
|
|
whichever non-root user happens to run the calling process (e.g. the web
|
|
interface). Falls back to installing with the calling process's own
|
|
interpreter if the wrapper isn't set up yet (the admin hasn't run
|
|
scripts/install/configure_web_sudo.sh), so dependency installation still
|
|
does *something* useful rather than hard-failing.
|
|
|
|
Always installs with the interpreter that will actually run the code
|
|
(``sys.executable`` in the fallback path, the wrapper's ``python3`` in the
|
|
sudo path) rather than a bare ``pip``/``pip3`` off PATH, which can
|
|
silently resolve to a different Python installation (e.g. system Python
|
|
vs. a virtualenv) than the one importing the package at runtime.
|
|
|
|
Args:
|
|
req_file: Path to a requirements.txt file
|
|
timeout: Subprocess timeout in seconds
|
|
|
|
Returns:
|
|
subprocess.CompletedProcess from the pip (or wrapper) invocation.
|
|
Never raises on a non-zero exit; callers should check ``returncode``.
|
|
``stdout`` is prefixed with an explanatory note when the root wrapper
|
|
was unavailable and the fallback path was used.
|
|
"""
|
|
project_root = Path(__file__).resolve().parent.parent.parent
|
|
wrapper = project_root / "scripts" / "fix_perms" / "safe_pip_install.sh"
|
|
|
|
if wrapper.exists():
|
|
# See sudo_remove_directory / configure_web_sudo.sh for why bash must
|
|
# be invoked with an explicit, known path rather than relying on the
|
|
# wrapper's shebang: sudoers matches the exact command line.
|
|
bash_candidates = []
|
|
for candidate in ("/usr/bin/bash", "/bin/bash", _shutil.which("bash")):
|
|
if candidate and candidate not in bash_candidates:
|
|
bash_candidates.append(candidate)
|
|
|
|
result = None
|
|
for bash_path in bash_candidates:
|
|
# bash_path and wrapper are fixed, known-good paths, and
|
|
# safe_pip_install.sh independently re-validates req_file is an
|
|
# allowed requirements.txt before installing anything as root.
|
|
result = subprocess.run( # nosec B603 - no shell invoked (list-form argv) # nosemgrep
|
|
["sudo", "-n", bash_path, str(wrapper), str(req_file)],
|
|
capture_output=True, text=True, timeout=timeout, cwd=str(project_root)
|
|
)
|
|
# Redact immediately: pip can echo a private index URL's embedded
|
|
# basic-auth credentials back in its own error/progress output
|
|
# (e.g. from a requirements.txt --index-url line). Doesn't affect
|
|
# the fixed-phrase "denied" check below -- those phrases never
|
|
# overlap with URL syntax.
|
|
result.stderr = _redact_url_credentials(result.stderr)
|
|
result.stdout = _redact_url_credentials(result.stdout)
|
|
if result.returncode == 0:
|
|
return result
|
|
# Distinguish "sudo rejected this exact command line" (worth
|
|
# trying the next bash candidate) from "sudo ran it but pip
|
|
# itself failed" (a real error — stop and surface it).
|
|
denied = any(phrase in result.stderr for phrase in SUDO_REFUSAL_PHRASES)
|
|
if not denied:
|
|
# Deliberately don't interpolate req_file or the pip output here:
|
|
# this log line is scanner-visible, and a static analyzer can't
|
|
# tell "already redacted above" from "still raw" just by looking
|
|
# at this call in isolation. The full (redacted) text is still
|
|
# available to callers via the returned CompletedProcess.
|
|
logger.warning(
|
|
"Root pip install failed (rc=%s); see the returned "
|
|
"CompletedProcess.stderr for details.",
|
|
result.returncode,
|
|
)
|
|
return result
|
|
|
|
# Same reasoning as above: no req_file / pip-output interpolation in
|
|
# this log line, only in the returned note/CompletedProcess.
|
|
logger.warning(
|
|
"Root pip install wrapper denied via sudo for all candidates; "
|
|
"falling back to user-level install. See the returned "
|
|
"CompletedProcess.stderr for details."
|
|
)
|
|
note = (
|
|
f"[Root install unavailable ({(result.stderr.strip() if result else 'sudo denied') or 'sudo denied'}); "
|
|
"installed for the current process's user only. Packages may not be "
|
|
"visible to ledmatrix.service if it runs as a different user — "
|
|
"run scripts/install/configure_web_sudo.sh to fix this.]\n"
|
|
)
|
|
else:
|
|
logger.warning(
|
|
"safe_pip_install.sh not found; falling back to user-level install."
|
|
)
|
|
note = (
|
|
"[safe_pip_install.sh not found; installed for the current process's "
|
|
"user only. Run scripts/install/configure_web_sudo.sh to enable "
|
|
"root installs visible to ledmatrix.service.]\n"
|
|
)
|
|
|
|
# sys.executable is this process's own interpreter (not
|
|
# attacker-influenced), and req_file is a Path built internally by callers
|
|
# (store_manager.py plugin paths, PROJECT_ROOT/requirements.txt), never
|
|
# raw external/user input. --ignore-installed matches safe_pip_install.sh:
|
|
# apt-managed packages (e.g. python3-requests) ship no pip RECORD file, so
|
|
# upgrading them would otherwise abort with "uninstall-no-record-file".
|
|
result = subprocess.run( # nosec B603 - no shell invoked (list-form argv) # nosemgrep
|
|
[sys.executable, "-m", "pip", "install", "--break-system-packages", "--ignore-installed", "-r", str(req_file)],
|
|
capture_output=True, text=True, timeout=timeout, cwd=str(project_root)
|
|
)
|
|
result.stderr = _redact_url_credentials(result.stderr)
|
|
result.stdout = note + _redact_url_credentials(result.stdout)
|
|
return result
|
|
|