diff options
Diffstat (limited to 'packages/meshbay-node')
| -rw-r--r-- | packages/meshbay-node/src/meshbay_node/daemon.py | 21 | ||||
| -rw-r--r-- | packages/meshbay-node/src/meshbay_node/platform.py | 80 | ||||
| -rw-r--r-- | packages/meshbay-node/tests/test_platform.py | 80 |
3 files changed, 176 insertions, 5 deletions
diff --git a/packages/meshbay-node/src/meshbay_node/daemon.py b/packages/meshbay-node/src/meshbay_node/daemon.py index b5a249d..37a2472 100644 --- a/packages/meshbay-node/src/meshbay_node/daemon.py +++ b/packages/meshbay-node/src/meshbay_node/daemon.py @@ -1634,9 +1634,15 @@ def _systemctl_user(verb: str, unit: str, *, not_running_hint: str, def main() -> None: import argparse - from meshbay_node.platform import configure_event_loop, force_utf8_stdio + from meshbay_node.platform import (configure_event_loop, force_utf8_stdio, + load_node_env) force_utf8_stdio() configure_event_loop() + # Before anything reads the environment. On Linux systemd has usually loaded + # the same file already via EnvironmentFile=; this is what makes a Windows + # run (Startup-folder .vbs, no systemd) and a bare `meshbay-node` behave the + # same. Already-set variables are left alone, so it cannot undo either. + load_node_env(config_dir()) parser = argparse.ArgumentParser(description="MeshBay Node daemon") parser.add_argument("command", nargs="?", @@ -1698,8 +1704,13 @@ def main() -> None: if args.command == "init": cfg_path = args.config or DEFAULT_CONFIG_PATH - config_dir = cfg_path.parent - config_dir.mkdir(parents=True, exist_ok=True) + cfg_dir = cfg_path.parent + cfg_dir.mkdir(parents=True, exist_ok=True) + + from meshbay_node.platform import install_node_env + env_written = install_node_env(cfg_dir) + if env_written: + print(f"Wrote {env_written} (packaged defaults).") hub_url = args.hub_url username = args.username @@ -1731,7 +1742,7 @@ def main() -> None: else: print(f"Config already exists: {cfg_path}") else: - unlock_file = config_dir / "unlock.key" + unlock_file = cfg_dir / "unlock.key" toml_lines = [ "[hub]", f'url = "{hub_url}"', @@ -1752,7 +1763,7 @@ def main() -> None: chmod_private(cfg_path) print(f"Config written to {cfg_path}") - unlock_file = config_dir / "unlock.key" + unlock_file = cfg_dir / "unlock.key" if not unlock_file.exists(): import secrets key = secrets.token_urlsafe(32) diff --git a/packages/meshbay-node/src/meshbay_node/platform.py b/packages/meshbay-node/src/meshbay_node/platform.py index b59418f..3c160a1 100644 --- a/packages/meshbay-node/src/meshbay_node/platform.py +++ b/packages/meshbay-node/src/meshbay_node/platform.py @@ -68,6 +68,86 @@ def state_dir() -> Path: return Path.home() / ".local" / "state" / "meshbay" +# ── Packaged defaults ──────────────────────────────────────────────────────── + + +def packaged_default_env() -> Path | None: + """ + The `default.env` shipped with the package: build-time defaults, currently + the shared read-only TMDB token. `init` copies it to config_dir()/node.env + and nothing reads it in place, so an operator's edits to their own copy + survive an upgrade. + + Frozen (PyInstaller/Windows): beside the executable, where + build-node-runtime.ps1 puts it -- the same placement it uses for ffmpeg. + Packaged (Linux): /opt/meshbay-node/share/default.env, from build-node.sh. + None in a source checkout, where no package wrote one. + """ + candidates = [] + if getattr(sys, "frozen", False): + candidates.append(Path(sys.executable).parent / "default.env") + candidates.append(Path("/opt/meshbay-node/share/default.env")) + for path in candidates: + try: + if path.is_file(): + return path + except OSError: + continue + return None + + +def install_node_env(target_dir: Path) -> Path | None: + """ + Copy the packaged default.env to <target_dir>/node.env, once, at init. + + Never overwrites: an existing node.env holds the operator's own values, and + silently replacing a configured token with the packaged one would be worse + than doing nothing. Returns the path when written, None when there was + nothing to copy or a file was already there. + """ + src = packaged_default_env() + if src is None: + return None + dest = target_dir / "node.env" + if dest.exists(): + return None + dest.write_bytes(src.read_bytes()) + chmod_private(dest) + return dest + + +def load_node_env(source_dir: Path) -> int: + """ + Read <source_dir>/node.env into os.environ, returning how many names were + set. + + systemd does this on Linux through `EnvironmentFile=`, but the Windows + autostart is a Startup-folder .vbs with no equivalent, so the daemon reads + the file itself and both platforms behave the same. An existing environment + variable always wins -- an operator exporting a value, or systemd having + already loaded the same file, overrides the packaged default rather than + being overridden by it. + """ + path = source_dir / "node.env" + try: + text = path.read_text(encoding="utf-8") + except (OSError, UnicodeDecodeError): + return 0 + count = 0 + for line in text.splitlines(): + line = line.strip() + if not line or line.startswith("#") or "=" not in line: + continue + name, _, value = line.partition("=") + name = name.strip() + value = value.strip().strip('"').strip("'") + if not name or name in os.environ: + continue + os.environ[name] = value + count += 1 + return count + + # ── File permissions ───────────────────────────────────────────────────────── diff --git a/packages/meshbay-node/tests/test_platform.py b/packages/meshbay-node/tests/test_platform.py index f9464c3..7042afb 100644 --- a/packages/meshbay-node/tests/test_platform.py +++ b/packages/meshbay-node/tests/test_platform.py @@ -5,6 +5,7 @@ here by monkeypatching that (and `os.environ`) rather than only on the OS the suite happens to run on. """ +import os import asyncio import sys from pathlib import Path @@ -177,3 +178,82 @@ def test_autostart_run_refuses_off_windows(monkeypatch): monkeypatch.setattr(sys, "platform", "linux") with pytest.raises(RuntimeError, match="Windows-only"): plat.autostart_run() + + +# ── Packaged defaults ──────────────────────────────────────────────────────── + +def test_frozen_build_finds_default_env_beside_the_executable(monkeypatch, tmp_path): + """Where build-node-runtime.ps1 puts it, alongside ffmpeg.""" + exe = tmp_path / "meshbay-node.exe" + exe.write_bytes(b"") + (tmp_path / "default.env").write_text("MESHBAY_TMDB_DEFAULT_TOKEN=eyJtest\n") + monkeypatch.setattr(sys, "frozen", True, raising=False) + monkeypatch.setattr(sys, "executable", str(exe)) + assert plat.packaged_default_env() == tmp_path / "default.env" + + +def test_source_checkout_has_no_packaged_default(monkeypatch, tmp_path): + monkeypatch.setattr(sys, "frozen", False, raising=False) + monkeypatch.setattr(sys, "executable", str(tmp_path / "python")) + monkeypatch.setattr(plat, "Path", Path) + # /opt/meshbay-node/share/default.env is absent on a dev machine + assert plat.packaged_default_env() is None + + +def test_install_node_env_copies_once(monkeypatch, tmp_path): + src = tmp_path / "default.env" + src.write_text("MESHBAY_TMDB_DEFAULT_TOKEN=eyJfirst\n") + monkeypatch.setattr(plat, "packaged_default_env", lambda: src) + cfg = tmp_path / "config" + cfg.mkdir() + + written = plat.install_node_env(cfg) + assert written == cfg / "node.env" + assert "eyJfirst" in written.read_text() + + +def test_install_node_env_never_overwrites_operator_values(monkeypatch, tmp_path): + """An existing node.env holds the operator's own token; clobbering it would + silently downgrade a configured node to the shared default.""" + src = tmp_path / "default.env" + src.write_text("MESHBAY_TMDB_DEFAULT_TOKEN=eyJpackaged\n") + monkeypatch.setattr(plat, "packaged_default_env", lambda: src) + cfg = tmp_path / "config" + cfg.mkdir() + (cfg / "node.env").write_text("MESHBAY_TMDB_DEFAULT_TOKEN=eyJoperator\n") + + assert plat.install_node_env(cfg) is None + assert "eyJoperator" in (cfg / "node.env").read_text() + + +def test_install_node_env_is_a_noop_without_a_package(monkeypatch, tmp_path): + monkeypatch.setattr(plat, "packaged_default_env", lambda: None) + assert plat.install_node_env(tmp_path) is None + assert not (tmp_path / "node.env").exists() + + +def test_load_node_env_sets_names(monkeypatch, tmp_path): + (tmp_path / "node.env").write_text( + "# a comment\n" + "\n" + "MESHBAY_TMDB_DEFAULT_TOKEN=eyJloaded\n" + 'QUOTED="value"\n' + ) + monkeypatch.delenv("MESHBAY_TMDB_DEFAULT_TOKEN", raising=False) + monkeypatch.delenv("QUOTED", raising=False) + assert plat.load_node_env(tmp_path) == 2 + assert os.environ["MESHBAY_TMDB_DEFAULT_TOKEN"] == "eyJloaded" + assert os.environ["QUOTED"] == "value" + + +def test_load_node_env_does_not_override_the_environment(monkeypatch, tmp_path): + """systemd may have loaded the same file already, and an operator export + must win over a packaged default.""" + (tmp_path / "node.env").write_text("MESHBAY_TMDB_DEFAULT_TOKEN=eyJfromfile\n") + monkeypatch.setenv("MESHBAY_TMDB_DEFAULT_TOKEN", "eyJfromenv") + assert plat.load_node_env(tmp_path) == 0 + assert os.environ["MESHBAY_TMDB_DEFAULT_TOKEN"] == "eyJfromenv" + + +def test_load_node_env_tolerates_a_missing_file(tmp_path): + assert plat.load_node_env(tmp_path) == 0 |