Apply restored owners, modes and times in an order that keeps them (closes #219)
check / check (push) Successful in 11m53s
check / check (push) Successful in 11m53s
A directory got its stored mode and mtime before its contents were written, so a read-only directory came back without its files and a non-empty one carried the time of the restore. Directories are now created owner-only (0700) and get their stored owner, mode and mtime after the restore loop, each before its parent, skipping any whose place a symlink has since taken. A file's mode is now applied after its chown, which on Linux clears setuid and setgid. A symlink gets its stored owner (as root) and mtime on the link itself, through golang.org/x/sys/unix, now a direct dependency. An interrupted restore leaves its directories at 0700. Model: opus-5-5
This commit was merged in pull request #245.
This commit is contained in:
+86
-16
@@ -10,11 +10,13 @@ import (
|
||||
"math"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"slices"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"filippo.io/age"
|
||||
"github.com/spf13/afero"
|
||||
"golang.org/x/sys/unix"
|
||||
"sneak.berlin/go/vaultik/internal/blobgen"
|
||||
"sneak.berlin/go/vaultik/internal/database"
|
||||
"sneak.berlin/go/vaultik/internal/log"
|
||||
@@ -63,6 +65,12 @@ const snapshotDBFilename = "snapshot.db"
|
||||
// directories themselves get their stored mode).
|
||||
const restoreDirMode = 0o755
|
||||
|
||||
// restoreDirCreateMode is the owner-only mode a directory from the
|
||||
// snapshot is created with during restore, so its contents can be written
|
||||
// whatever its stored mode. The stored mode is applied after the restore
|
||||
// loop, by applyDirectoryMetadata.
|
||||
const restoreDirCreateMode = 0o700
|
||||
|
||||
// restoreFileMode is the restrictive mode a regular file is created with
|
||||
// during restore. Content is written while the file holds this mode; the
|
||||
// stored mode is applied only after the file is fully written and closed,
|
||||
@@ -332,6 +340,8 @@ func (v *Vaultik) restoreAllFiles(
|
||||
return nil, err
|
||||
}
|
||||
|
||||
session.applyDirectoryMetadata()
|
||||
|
||||
return result, nil
|
||||
}
|
||||
|
||||
@@ -901,6 +911,9 @@ type restoreSession struct {
|
||||
// the call entirely as non-root and emit one warning at the end
|
||||
// of the restore explaining that ownership was not preserved.
|
||||
runningAsRoot bool
|
||||
// directories holds every restored directory, for
|
||||
// applyDirectoryMetadata to finish after the restore loop.
|
||||
directories []*database.File
|
||||
}
|
||||
|
||||
// containedRestorePath resolves rel — a path read from the snapshot
|
||||
@@ -1007,6 +1020,8 @@ func (s *restoreSession) restoreSymlink(file *database.File, targetPath string)
|
||||
if err != nil {
|
||||
return fmt.Errorf("creating symlink: %w", err)
|
||||
}
|
||||
|
||||
s.applySymlinkMetadata(file, targetPath)
|
||||
} else {
|
||||
log.Debug("Symlink creation not supported on this filesystem",
|
||||
"path", file.Path, "target", file.LinkTarget)
|
||||
@@ -1019,35 +1034,90 @@ func (s *restoreSession) restoreSymlink(file *database.File, targetPath string)
|
||||
return nil
|
||||
}
|
||||
|
||||
// restoreDirectory restores a directory with its permissions, mtime,
|
||||
// and (on real filesystems, with sufficient privileges) ownership.
|
||||
// restoreDirectory creates a directory with restoreDirCreateMode. Its
|
||||
// stored mode, owner and mtime are applied after the restore loop by
|
||||
// applyDirectoryMetadata: a read-only stored mode would block writing
|
||||
// its contents, and writing them changes its mtime.
|
||||
func (s *restoreSession) restoreDirectory(
|
||||
file *database.File, targetPath string,
|
||||
) error {
|
||||
err := s.v.Fs.MkdirAll(targetPath, os.FileMode(file.Mode))
|
||||
err := s.v.Fs.MkdirAll(targetPath, restoreDirCreateMode)
|
||||
if err != nil {
|
||||
return fmt.Errorf("creating directory: %w", err)
|
||||
}
|
||||
|
||||
// MkdirAll applies the process umask, so chmod to the exact stored
|
||||
// mode. A failure here is non-fatal.
|
||||
err = s.v.Fs.Chmod(targetPath, os.FileMode(file.Mode))
|
||||
if err != nil {
|
||||
log.Debug("Failed to set permissions", "path", targetPath, "error", err)
|
||||
}
|
||||
|
||||
s.applyFileMetadata(file, targetPath)
|
||||
s.directories = append(s.directories, file)
|
||||
|
||||
s.result.FilesRestored++
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// applyDirectoryMetadata applies the stored owner, mtime and mode to every
|
||||
// restored directory, each before its parent, so a parent whose stored
|
||||
// mode denies search does not block its children. Failures are logged at
|
||||
// debug level and do not abort the restore.
|
||||
func (s *restoreSession) applyDirectoryMetadata() {
|
||||
// A path sorts after its parent's, so reverse order puts every
|
||||
// directory before its parent.
|
||||
slices.SortFunc(s.directories, func(a, b *database.File) int {
|
||||
return strings.Compare(b.Path.String(), a.Path.String())
|
||||
})
|
||||
|
||||
for _, dir := range s.directories {
|
||||
targetPath, err := containedRestorePath(
|
||||
s.v.Fs, s.opts.TargetDir, dir.Path.String())
|
||||
if err != nil {
|
||||
log.Debug("Failed to set directory metadata",
|
||||
"path", dir.Path, "error", err)
|
||||
|
||||
continue
|
||||
}
|
||||
|
||||
// A later entry can have put a symlink in the directory's place,
|
||||
// for example one stored as "/d/" next to the directory "/d". The
|
||||
// calls below follow symlinks, so they would change its target.
|
||||
info, err := lstatIfPossible(s.v.Fs, targetPath)
|
||||
if err != nil || !info.IsDir() {
|
||||
log.Debug("Not setting directory metadata: no longer a directory",
|
||||
"path", targetPath, "error", err)
|
||||
|
||||
continue
|
||||
}
|
||||
|
||||
s.applyFileMetadata(dir, targetPath)
|
||||
|
||||
err = s.v.Fs.Chmod(targetPath, os.FileMode(dir.Mode))
|
||||
if err != nil {
|
||||
log.Debug("Failed to set permissions", "path", targetPath, "error", err)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// applySymlinkMetadata applies ownership (when running as root) and mtime
|
||||
// to a restored symlink itself; os.Chown and Chtimes would follow it.
|
||||
// Failures are logged at debug level and do not abort the restore.
|
||||
func (s *restoreSession) applySymlinkMetadata(file *database.File, targetPath string) {
|
||||
if s.runningAsRoot {
|
||||
err := os.Lchown(targetPath, int(file.UID), int(file.GID))
|
||||
if err != nil {
|
||||
log.Debug("Failed to set ownership", "path", targetPath, "error", err)
|
||||
}
|
||||
}
|
||||
|
||||
mtime := unix.NsecToTimeval(file.MTime.UnixNano())
|
||||
|
||||
err := unix.Lutimes(targetPath, []unix.Timeval{mtime, mtime})
|
||||
if err != nil {
|
||||
log.Debug("Failed to set mtime", "path", targetPath, "error", err)
|
||||
}
|
||||
}
|
||||
|
||||
// applyFileMetadata applies ownership (when running as root on a real
|
||||
// filesystem) and mtime to a restored path. Permission mode is applied
|
||||
// separately by each caller, with different failure handling, so it is
|
||||
// not touched here. Failures are logged at debug level and do not abort
|
||||
// the restore.
|
||||
// filesystem) and mtime to a restored path. The caller applies the mode
|
||||
// afterwards: on Linux a chown clears the setuid and setgid bits of a
|
||||
// regular file. Failures are logged at debug level and do not abort the
|
||||
// restore.
|
||||
func (s *restoreSession) applyFileMetadata(file *database.File, targetPath string) {
|
||||
if s.runningAsRoot {
|
||||
if _, ok := s.v.Fs.(*afero.OsFs); ok {
|
||||
@@ -1138,8 +1208,8 @@ func (s *restoreSession) restoreRegularFile(
|
||||
return fmt.Errorf("closing output file: %w", err)
|
||||
}
|
||||
|
||||
s.applyRestoredFileMode(file, targetPath)
|
||||
s.applyFileMetadata(file, targetPath)
|
||||
s.applyRestoredFileMode(file, targetPath)
|
||||
|
||||
s.result.FilesRestored++
|
||||
s.result.BytesRestored += bytesWritten
|
||||
|
||||
Reference in New Issue
Block a user