diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-02 11:22:23 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-02 11:22:23 +0200 |
| commit | 19a7201d1d911c9f25bc112a3e0d2218eb6c14a2 (patch) | |
| tree | d0c58e614db161dfa25a6219db0eaeaa97a80e76 /packaging/deb/meshbay-hub | |
| parent | 9c1b622611bb0b21852d3c9c11e1d8674aa35654 (diff) | |
| download | meshbay-19a7201d1d911c9f25bc112a3e0d2218eb6c14a2.tar.gz | |
fix(packaging): ship the example hub config, and stop leaving /etc/meshbay open
Three defects, found while answering whether installing the .deb would land
where the production server was just moved to by hand.
- **The example config was never packaged.** `build-hub.sh` copied
`packaging/conf/hub.toml.example` under `if [ -f ]`, and that path does not
exist in this repo — so every package ever built shipped no example at all
and said nothing about it. The postinst places no config either, on purpose
(a shipped hub.toml is overwritten on upgrade; a shipped secret gets run in
production), which left an installed hub with nothing to copy from. The file
now exists, documents every key `config.py` reads including the captcha
`allowed_hosts` the desktop client needs, and the copy is a hard failure
rather than a silent skip.
- **`/etc/meshbay` was created 0755.** It holds the hub's Ed25519 private key
and its database password. The file modes protect the contents, but a
world-listable config directory tells anyone with a shell what a hub keeps
and where. Now 0750 root:meshbay, in both the deb postinst and the rpm
scriptlet; the service reads it by group.
- **The rpm would have failed to build on the new file.** `%files` claimed
nothing under /etc, and rpmbuild refuses an installed file no line claims.
It now declares the directory and the example, with explicit `%attr` and
`%config` so an operator's edits become .rpmsave rather than vanishing.
Package modes no longer follow the builder's umask either — the same source
tree produced 775/664 on a machine with umask 002 and 755/644 with 022.
`install -m` sets them.
Verified by building: the deb now carries ./etc/meshbay/ at drwxr-x--- with
hub.toml.example at 0644, and the embedded postinst tightens the directory as
belt and braces rather than as the only thing making it right. The rpm path is
unverified — no rpmbuild on this machine.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014UtzVrzM7e2tG9fSpkR9ML
Diffstat (limited to 'packaging/deb/meshbay-hub')
| -rw-r--r-- | packaging/deb/meshbay-hub/DEBIAN/postinst | 11 |
1 files changed, 9 insertions, 2 deletions
diff --git a/packaging/deb/meshbay-hub/DEBIAN/postinst b/packaging/deb/meshbay-hub/DEBIAN/postinst index 3cf66a9..0484f3b 100644 --- a/packaging/deb/meshbay-hub/DEBIAN/postinst +++ b/packaging/deb/meshbay-hub/DEBIAN/postinst @@ -17,8 +17,15 @@ case "$1" in install -d -o meshbay -g meshbay -m 750 /var/lib/meshbay/hub install -d -o meshbay -g meshbay -m 750 /var/log/meshbay - # Create config directory (files are placed by the admin, not by us) - install -d -m 755 /etc/meshbay + # Create config directory (files are placed by the admin, not by us — + # a shipped hub.toml would be overwritten on upgrade, and a shipped + # secret would be run in production). The example lands in + # /etc/meshbay/hub.toml.example instead. + # 750, not 755: this directory holds the hub's private key and its + # database password. The file modes protect the contents, but a + # world-listable config directory tells anyone with a shell what a + # hub keeps and where. The service reads it by group. + install -d -o root -g meshbay -m 750 /etc/meshbay # Reload systemd if available if [ -d /run/systemd/system ]; then |