fix: allow service-owned data directory during uninstall
TallyNote release / linux-x64 (push) Successful in 5m55s

This commit is contained in:
Qiufeng
2026-09-02 06:54:36 +08:00
parent bac10b6fdf
commit 3cedcb901b
5 changed files with 41 additions and 20 deletions
+9 -2
View File
@@ -10,6 +10,7 @@ umask 077
TEST_MODE=${TALLYNOTE_UNINSTALL_TEST_MODE:-false}
TEST_ROOT=${TALLYNOTE_UNINSTALL_ROOT:-}
TEST_DATA_OWNER_UID=${TALLYNOTE_UNINSTALL_TEST_DATA_OWNER_UID:-}
PREFIX=${TALLYNOTE_PREFIX:-/opt/tallynote}
DATA_DIR=${TALLYNOTE_DATA_DIR:-/var/lib/tallynote}
CONFIG_DIR=${TALLYNOTE_CONFIG_DIR:-/etc/tallynote}
@@ -103,7 +104,7 @@ allowed_data_owner() {
local path=$1 uid tallynote_uid
uid=$(stat_uid "$path")
if [[ "$TEST_MODE" == true ]]; then
[[ "$uid" == "$(id -u)" || "$uid" == 0 ]]
[[ "$uid" == "$(id -u)" || "$uid" == 0 || ( -n "$TEST_DATA_OWNER_UID" && "$uid" == "$TEST_DATA_OWNER_UID" ) ]]
return
fi
[[ "$uid" == 0 ]] && return 0
@@ -130,7 +131,13 @@ validate_parent_chain() {
if [[ -L "$current" ]]; then die "路径不能包含符号链接:$current"; fi
if [[ -e "$current" ]]; then
[[ -d "$current" ]] || die "路径不是目录:$current"
allowed_owner "$current" || die "路径目录的所有者不受信任:$current"
# The target itself is checked by validate_target with its path-specific
# owner policy (data may belong to the tallynote service user). Keep all
# ancestor directories root-owned, but do not apply that policy twice to
# the final target.
if [[ "$current" != "$target" ]]; then
allowed_owner "$current" || die "路径目录的所有者不受信任:$current"
fi
local mode_bits
mode_bits=$(stat_mode_bits "$current")
(( (mode_bits & 18) == 0 || (mode_bits & 512) != 0 )) || die "路径目录权限过宽:$current"