Server: Make unix socket permission configurable (#52944)

This commit is contained in:
unknowndevQwQ
2022-11-01 15:04:01 +01:00
committed by GitHub
parent 44069b64cd
commit 6dd3584f77
5 changed files with 42 additions and 3 deletions
+8 -2
View File
@@ -470,8 +470,14 @@ func (hs *HTTPServer) getListener() (net.Listener, error) {
// Make socket writable by group
// nolint:gosec
if err := os.Chmod(hs.Cfg.SocketPath, 0660); err != nil {
return nil, fmt.Errorf("failed to change socket permissions: %w", err)
if err := os.Chmod(hs.Cfg.SocketPath, os.FileMode(hs.Cfg.SocketMode)); err != nil {
return nil, fmt.Errorf("failed to change socket mode %d: %w", hs.Cfg.SocketMode, err)
}
// golang.org/pkg/os does not have chgrp
// Changing the gid of a file without privileges requires that the target group is in the group of the process and that the process is the file owner
if err := os.Chown(hs.Cfg.SocketPath, -1, hs.Cfg.SocketGid); err != nil {
return nil, fmt.Errorf("failed to change socket group id %d: %w", hs.Cfg.SocketGid, err)
}
return listener, nil