summaryrefslogtreecommitdiffstats
path: root/packaging/build/build-hub.sh
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-02 11:22:23 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-02 11:22:23 +0200
commit19a7201d1d911c9f25bc112a3e0d2218eb6c14a2 (patch)
treed0c58e614db161dfa25a6219db0eaeaa97a80e76 /packaging/build/build-hub.sh
parent9c1b622611bb0b21852d3c9c11e1d8674aa35654 (diff)
downloadmeshbay-19a7201d1d911c9f25bc112a3e0d2218eb6c14a2.tar.gz
fix(packaging): ship the example hub config, and stop leaving /etc/meshbay open
Three defects, found while answering whether installing the .deb would land where the production server was just moved to by hand. - **The example config was never packaged.** `build-hub.sh` copied `packaging/conf/hub.toml.example` under `if [ -f ]`, and that path does not exist in this repo — so every package ever built shipped no example at all and said nothing about it. The postinst places no config either, on purpose (a shipped hub.toml is overwritten on upgrade; a shipped secret gets run in production), which left an installed hub with nothing to copy from. The file now exists, documents every key `config.py` reads including the captcha `allowed_hosts` the desktop client needs, and the copy is a hard failure rather than a silent skip. - **`/etc/meshbay` was created 0755.** It holds the hub's Ed25519 private key and its database password. The file modes protect the contents, but a world-listable config directory tells anyone with a shell what a hub keeps and where. Now 0750 root:meshbay, in both the deb postinst and the rpm scriptlet; the service reads it by group. - **The rpm would have failed to build on the new file.** `%files` claimed nothing under /etc, and rpmbuild refuses an installed file no line claims. It now declares the directory and the example, with explicit `%attr` and `%config` so an operator's edits become .rpmsave rather than vanishing. Package modes no longer follow the builder's umask either — the same source tree produced 775/664 on a machine with umask 002 and 755/644 with 022. `install -m` sets them. Verified by building: the deb now carries ./etc/meshbay/ at drwxr-x--- with hub.toml.example at 0644, and the embedded postinst tightens the directory as belt and braces rather than as the only thing making it right. The rpm path is unverified — no rpmbuild on this machine. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014UtzVrzM7e2tG9fSpkR9ML
Diffstat (limited to 'packaging/build/build-hub.sh')
-rwxr-xr-xpackaging/build/build-hub.sh27
1 files changed, 18 insertions, 9 deletions
diff --git a/packaging/build/build-hub.sh b/packaging/build/build-hub.sh
index 45d2ab9..be2d363 100755
--- a/packaging/build/build-hub.sh
+++ b/packaging/build/build-hub.sh
@@ -53,17 +53,26 @@ if [ -f "$REPO/packages/meshbay-hub/alembic.ini" ]; then
cp "$REPO/packages/meshbay-hub/alembic.ini" "$ROOT/opt/meshbay-hub/migrations/"
fi
-# Config example
+# Config example.
+#
+# A hard failure, not an `if [ -f ]`. This was a silent skip against a path
+# that did not exist, so every package built shipped no example config at all
+# and said nothing about it — and the postinst places no config either, on
+# purpose, which left an installed hub with nothing to copy from.
+EXAMPLE="$REPO/packaging/conf/hub.toml.example"
+[ -f "$EXAMPLE" ] || { echo "!! missing $EXAMPLE" >&2; exit 1; }
mkdir -p "$ROOT/opt/meshbay-hub/share"
-if [ -f "$REPO/packaging/conf/hub.toml.example" ]; then
- cp "$REPO/packaging/conf/hub.toml.example" "$ROOT/opt/meshbay-hub/share/"
-fi
+install -m 644 "$EXAMPLE" "$ROOT/opt/meshbay-hub/share/"
-# Also install to /etc/meshbay/ for discoverability
-mkdir -p "$ROOT/etc/meshbay"
-if [ -f "$ROOT/opt/meshbay-hub/share/hub.toml.example" ]; then
- cp "$ROOT/opt/meshbay-hub/share/hub.toml.example" "$ROOT/etc/meshbay/"
-fi
+# Also next to the real config, where an operator looks first. Never
+# hub.toml itself: an upgrade would overwrite a working deployment.
+#
+# Modes are set here rather than left to the builder's umask, which decided
+# them until now — 775/664 on a machine with umask 002, 755/644 on one with
+# 022, from the same source tree. The postinst tightens the directory too, but
+# that then repairs the package instead of the package being right.
+install -d -m 750 "$ROOT/etc/meshbay"
+install -m 644 "$ROOT/opt/meshbay-hub/share/hub.toml.example" "$ROOT/etc/meshbay/"
# --- Systemd unit ---------------------------------------------------------
mkdir -p "$ROOT/usr/lib/systemd/system"