diff --git a/fleetd/src/main/java/dev/ltms/fleet/member/EnvAllowListScrub.java b/fleetd/src/main/java/dev/ltms/fleet/member/EnvAllowListScrub.java index 280636d..6938115 100644 --- a/fleetd/src/main/java/dev/ltms/fleet/member/EnvAllowListScrub.java +++ b/fleetd/src/main/java/dev/ltms/fleet/member/EnvAllowListScrub.java @@ -105,9 +105,9 @@ public final class EnvAllowListScrub { reapOrphans(parentDir); Path dir = Files.createTempDirectory(parentDir, DIR_PREFIX); dir.toFile().deleteOnExit(); - // The report is written by zsh, after these hooks are registered, so register its path - // too — otherwise the directory is non-empty at JVM exit and cannot be removed at all. - dir.resolve(REPORT_FILE).toFile().deleteOnExit(); + // zsh truncates this pre-created receipt after these hooks are registered. Register its + // path too — otherwise the directory is non-empty at JVM exit and cannot be removed. + Files.createFile(dir.resolve(REPORT_FILE)).toFile().deleteOnExit(); write(dir, SCRUB_FILE, scrubScript(allowedNames)); write(dir, ".zshenv", homeSourcingFile(".zshenv")); write(dir, ".zprofile", homeSourcingFile(".zprofile")); @@ -147,12 +147,11 @@ public final class EnvAllowListScrub { * into it: owner keeps full access, {@code group} gets traverse+read on the directory ({@code * rwxr-x---}, so a member process — a login shell reading it via {@code ZDOTDIR}, or another * process simply opening a file under it — running under that group can find and read the - * files) and read-only on each file ({@code rw-r-----}) — deliberately no group WRITE anywhere, - * since a member never needs to add or change what fleetd generated. (For the ZDOTDIR scrub - * specifically, this also means the scrub script's own report write inside the pane fails - * closed rather than open — see {@code scrub.zsh}'s trailing {@code 2>/dev/null} — which {@link - * dev.ltms.fleet.member.HerdrPeerLauncher#releaseZdotdir} already treats as "cannot be - * confirmed to have run" rather than success.) + * files) and read-only on each file ({@code rw-r-----}), except the pre-created ZDOTDIR + * {@code scrub-report.txt}. That receipt gets group write ({@code rw-rw----}), so + * {@code scrub.zsh} can truncate and write it without granting group write on the directory. + * If its optional permission change fails, the member cannot write a receipt and the launcher + * keeps its existing WARN rather than failing the spawn. * *
Package-private and named generically on purpose: fleetd #213 built this for the ZDOTDIR
* scrub directory, and fleetd #219 reuses it verbatim for {@link
@@ -167,7 +166,15 @@ public final class EnvAllowListScrub {
setGroupAndPermissions(dir, principal, "rwxr-x---");
try (Stream