From d516a0b563ad1979068dd2590f601c3973f219cc Mon Sep 17 00:00:00 2001 From: asepharyana Date: Wed, 9 Sep 2026 21:09:02 +0700 Subject: [PATCH] fix(health-check): handle PermissionError on on-disk key file MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit File is pr-agent:pr-agent 0600 — code user can't read directly. Added sudo -n cat fallback for the on-disk key file, matching the existing pattern used for /etc/bws-token. Key resolution order: 1. Direct read (works when gateway has bws group) 2. sudo -n cat (works with NOPASSWD sudo) 3. BWS CLI fallback --- src/health-check.py | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/src/health-check.py b/src/health-check.py index f8dfbf8..0228385 100644 --- a/src/health-check.py +++ b/src/health-check.py @@ -55,7 +55,8 @@ KEYFILE = APP_DIR / "omniroute_key" def _read_key_from_disk() -> str: """Read the router key from the on-disk file maintained by sync-key.py. - This is the primary source — always current after service start.""" + This is the primary source — always current after service start. + File is pr-agent:pr-agent 0600, so non-root processes use sudo.""" try: if KEYFILE.is_file(): key = KEYFILE.read_text().strip() @@ -63,6 +64,18 @@ def _read_key_from_disk() -> str: return key except (PermissionError, OSError): pass + # Fallback: sudo (works when user has NOPASSWD sudo or bws group) + try: + r = subprocess.run( + ["sudo", "-n", "cat", str(KEYFILE)], + capture_output=True, text=True, timeout=10, + ) + if r.returncode == 0: + key = r.stdout.strip() + if len(key) >= 10: + return key + except Exception: + pass return ""