fix(health-check): handle PermissionError on on-disk key file
File is pr-agent:pr-agent 0600 — code user can't read directly. Added sudo -n cat fallback for the on-disk key file, matching the existing pattern used for /etc/bws-token. Key resolution order: 1. Direct read (works when gateway has bws group) 2. sudo -n cat (works with NOPASSWD sudo) 3. BWS CLI fallback
This commit is contained in:
+14
-1
@@ -55,7 +55,8 @@ KEYFILE = APP_DIR / "omniroute_key"
|
|||||||
|
|
||||||
def _read_key_from_disk() -> str:
|
def _read_key_from_disk() -> str:
|
||||||
"""Read the router key from the on-disk file maintained by sync-key.py.
|
"""Read the router key from the on-disk file maintained by sync-key.py.
|
||||||
This is the primary source — always current after service start."""
|
This is the primary source — always current after service start.
|
||||||
|
File is pr-agent:pr-agent 0600, so non-root processes use sudo."""
|
||||||
try:
|
try:
|
||||||
if KEYFILE.is_file():
|
if KEYFILE.is_file():
|
||||||
key = KEYFILE.read_text().strip()
|
key = KEYFILE.read_text().strip()
|
||||||
@@ -63,6 +64,18 @@ def _read_key_from_disk() -> str:
|
|||||||
return key
|
return key
|
||||||
except (PermissionError, OSError):
|
except (PermissionError, OSError):
|
||||||
pass
|
pass
|
||||||
|
# Fallback: sudo (works when user has NOPASSWD sudo or bws group)
|
||||||
|
try:
|
||||||
|
r = subprocess.run(
|
||||||
|
["sudo", "-n", "cat", str(KEYFILE)],
|
||||||
|
capture_output=True, text=True, timeout=10,
|
||||||
|
)
|
||||||
|
if r.returncode == 0:
|
||||||
|
key = r.stdout.strip()
|
||||||
|
if len(key) >= 10:
|
||||||
|
return key
|
||||||
|
except Exception:
|
||||||
|
pass
|
||||||
return ""
|
return ""
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user