fix(health-check): handle PermissionError on on-disk key file
File is pr-agent:pr-agent 0600 — code user can't read directly. Added sudo -n cat fallback for the on-disk key file, matching the existing pattern used for /etc/bws-token. Key resolution order: 1. Direct read (works when gateway has bws group) 2. sudo -n cat (works with NOPASSWD sudo) 3. BWS CLI fallback
This commit is contained in:
+14
-1
@@ -55,7 +55,8 @@ KEYFILE = APP_DIR / "omniroute_key"
|
||||
|
||||
def _read_key_from_disk() -> str:
|
||||
"""Read the router key from the on-disk file maintained by sync-key.py.
|
||||
This is the primary source — always current after service start."""
|
||||
This is the primary source — always current after service start.
|
||||
File is pr-agent:pr-agent 0600, so non-root processes use sudo."""
|
||||
try:
|
||||
if KEYFILE.is_file():
|
||||
key = KEYFILE.read_text().strip()
|
||||
@@ -63,6 +64,18 @@ def _read_key_from_disk() -> str:
|
||||
return key
|
||||
except (PermissionError, OSError):
|
||||
pass
|
||||
# Fallback: sudo (works when user has NOPASSWD sudo or bws group)
|
||||
try:
|
||||
r = subprocess.run(
|
||||
["sudo", "-n", "cat", str(KEYFILE)],
|
||||
capture_output=True, text=True, timeout=10,
|
||||
)
|
||||
if r.returncode == 0:
|
||||
key = r.stdout.strip()
|
||||
if len(key) >= 10:
|
||||
return key
|
||||
except Exception:
|
||||
pass
|
||||
return ""
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user