fix(health-check): handle PermissionError on on-disk key file

File is pr-agent:pr-agent 0600 — code user can't read directly.
Added sudo -n cat fallback for the on-disk key file, matching the
existing pattern used for /etc/bws-token. Key resolution order:
1. Direct read (works when gateway has bws group)
2. sudo -n cat (works with NOPASSWD sudo)
3. BWS CLI fallback
This commit is contained in:
asepharyana
2026-09-09 21:09:02 +07:00
parent ae5356a4ea
commit d516a0b563
+14 -1
View File
@@ -55,7 +55,8 @@ KEYFILE = APP_DIR / "omniroute_key"
def _read_key_from_disk() -> str: def _read_key_from_disk() -> str:
"""Read the router key from the on-disk file maintained by sync-key.py. """Read the router key from the on-disk file maintained by sync-key.py.
This is the primary source — always current after service start.""" This is the primary source — always current after service start.
File is pr-agent:pr-agent 0600, so non-root processes use sudo."""
try: try:
if KEYFILE.is_file(): if KEYFILE.is_file():
key = KEYFILE.read_text().strip() key = KEYFILE.read_text().strip()
@@ -63,6 +64,18 @@ def _read_key_from_disk() -> str:
return key return key
except (PermissionError, OSError): except (PermissionError, OSError):
pass pass
# Fallback: sudo (works when user has NOPASSWD sudo or bws group)
try:
r = subprocess.run(
["sudo", "-n", "cat", str(KEYFILE)],
capture_output=True, text=True, timeout=10,
)
if r.returncode == 0:
key = r.stdout.strip()
if len(key) >= 10:
return key
except Exception:
pass
return "" return ""