| 183 | } |
| 184 | |
| 185 | void Server::run() |
| 186 | { |
| 187 | |
| 188 | std::error_code ec; |
| 189 | { |
| 190 | #ifndef WINDSCRIBE_DEV_MODE |
| 191 | UmaskGuard guard(0067); |
| 192 | #else |
| 193 | UmaskGuard guard(0); |
| 194 | #endif |
| 195 | std::filesystem::create_directories(WS_LINUX_RUN_DIR, ec); |
| 196 | } |
| 197 | if (ec) { |
| 198 | spdlog::error("Failed to create " WS_LINUX_RUN_DIR ": {}", ec.message()); |
| 199 | } |
| 200 | #ifndef WINDSCRIBE_DEV_MODE // secure (non-dev) |
| 201 | // Force uid=0 (not (uid_t)-1) so a pre-existing dir with a wrong owner is self-healed before |
| 202 | // permissions runs — otherwise the chmod could hand owner-write to that wrong owner. |
| 203 | if (struct group *grp = getgrnam(WS_PRODUCT_NAME_LOWER)) { |
| 204 | if (::lchown(WS_LINUX_RUN_DIR, 0, grp->gr_gid) != 0) { |
| 205 | spdlog::error("Failed to chown " WS_LINUX_RUN_DIR ": {}", IO::strerror(errno)); |
| 206 | } |
| 207 | } else { |
| 208 | spdlog::error("Could not get group info for " WS_PRODUCT_NAME_LOWER); |
| 209 | } |
| 210 | std::filesystem::permissions(WS_LINUX_RUN_DIR, |
| 211 | std::filesystem::perms::owner_all | std::filesystem::perms::group_exec, |
| 212 | ec); |
| 213 | #else // dev mode |
| 214 | std::filesystem::permissions(WS_LINUX_RUN_DIR, |
| 215 | std::filesystem::perms::owner_all | std::filesystem::perms::group_all | std::filesystem::perms::others_all, |
| 216 | ec); |
| 217 | #endif |
| 218 | if (ec) { |
| 219 | spdlog::error("Failed to set permissions on " WS_LINUX_RUN_DIR ": {}", ec.message()); |
| 220 | } |
| 221 | { |
| 222 | #ifndef WINDSCRIBE_DEV_MODE |
| 223 | UmaskGuard guard(0077); |
| 224 | #else |
| 225 | UmaskGuard guard(0); |
| 226 | #endif |
| 227 | std::filesystem::create_directories(WS_LINUX_TMP_DIR, ec); |
| 228 | } |
| 229 | if (ec) { |
| 230 | spdlog::error("Failed to create " WS_LINUX_TMP_DIR ": {}", ec.message()); |
| 231 | } |
| 232 | #ifndef WINDSCRIBE_DEV_MODE // secure (non-dev) |
| 233 | if (struct group *grp = getgrnam(WS_PRODUCT_NAME_LOWER)) { |
| 234 | if (::lchown(WS_LINUX_TMP_DIR, 0, grp->gr_gid) != 0) { |
| 235 | spdlog::error("Failed to chown " WS_LINUX_TMP_DIR ": {}", IO::strerror(errno)); |
| 236 | } |
| 237 | } else { |
| 238 | spdlog::error("Could not get group info for " WS_PRODUCT_NAME_LOWER); |
| 239 | } |
| 240 | std::filesystem::permissions(WS_LINUX_TMP_DIR, std::filesystem::perms::owner_all, ec); |
| 241 | #else // dev mode |
| 242 | std::filesystem::permissions(WS_LINUX_TMP_DIR, |
no test coverage detected