fix: root-safe www-data chown after builds and config sync
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m0s

This commit is contained in:
openhands committed 2026-08-03 19:12:22 +02:00
1 parent 2fba923a3a
commit cf89681576
1 file changed
+25 -9
+25 -9
View File
@@ -1144,6 +1144,7 @@ update_renderer() {
else
info "Renderer: already up to date"
fi
fix_perms
return 0
}
@@ -1181,6 +1182,7 @@ update_client() {
fi
mkdir -p "$NITRO_CLIENT/dist/custom-themes"
[ ! -f "$NITRO_CLIENT/dist/custom-themes/index.json" ] && echo '{"themes":[]}' > "$NITRO_CLIENT/dist/custom-themes/index.json"
fix_perms
return 0
}
@@ -1273,6 +1275,7 @@ for path in paths:
if command -v redis-cli &>/dev/null; then
redis-cli FLUSHALL 2>/dev/null && ok "Redis cache flushed" || true
fi
fix_perms
}
do_cleanup() {
@@ -1293,12 +1296,27 @@ do_cleanup() {
ok "Cleanup done (%s logs removed)" "$lc"
}
fix_perms() {
# Make build output web-servable no matter which user ran the build.
# Running as root we chown directly; otherwise use `sudo -n` (no TTY, so it
# also works from cron). Never silently swallow failures.
local runner=""
[ "$(id -u)" -eq 0 ] || runner="sudo -n"
local changed=false
for d in "$NITRO_CLIENT" "$NITRO_RENDERER" "$GAMEDATA_CONF_DIR"; do
[ -d "$d" ] || continue
if $runner chown -R www-data:www-data "$d" 2>/dev/null; then
changed=true
else
warn "Could not chown %s to www-data:www-data" "$d"
fi
done
[ "$changed" = true ] && ok "Permissions set"
}
do_permissions() {
step 7 8 "Set Permissions"
for d in "$NITRO_CLIENT" "$NITRO_RENDERER" "$EMULATOR_DIR" "$GAMEDATA_CONF_DIR"; do
[ -d "$d" ] && sudo chown -R www-data:www-data "$d" 2>/dev/null || true
done
ok "Permissions set"
fix_perms
}
do_restart() {
@@ -1428,7 +1446,7 @@ cmd_update() {
esac
show_summary
sudo chown -R www-data:www-data "$NITRO_CLIENT/"
fix_perms
release_lock
}
@@ -1671,9 +1689,7 @@ cmd_flyaway_repair() {
# Fix permissions
step 3 6 "$(_t "Set Permissions")"
for d in "$NITRO_CLIENT" "$NITRO_RENDERER" "$EMULATOR_DIR" "$GAMEDATA_CONF_DIR"; do
[ -d "$d" ] && sudo chown -R www-data:www-data "$d" 2>/dev/null || true
done
fix_perms
ok "Permissions fixed"
# Sync / validate configs
@@ -1721,7 +1737,7 @@ cmd_flyaway_repair() {
do_restart
show_summary
sudo chown -R www-data:www-data "$NITRO_CLIENT/"
fix_perms
release_lock
}