mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
Require root-owned, non-group/other-writable pmg for --system install; allow remove without that validation. Doctor checks npm resolution for PATH precedence, uses ImpliesInterception instead of message matching, and documents version-manager shadowing. Pass profile bin dir from the shim manager and note that system config ignores per-user files. Co-authored-by: Cursor <cursoragent@cursor.com>
213 lines
5.7 KiB
Go
213 lines
5.7 KiB
Go
package shim
|
|
|
|
import (
|
|
"fmt"
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
|
|
"github.com/safedep/pmg/internal/alias"
|
|
)
|
|
|
|
const (
|
|
defaultSystemBinDir = "/usr/local/lib/pmg/bin"
|
|
defaultSystemProfilePath = "/etc/profile.d/pmg.sh"
|
|
systemProfileMarker = "PMG system shims"
|
|
)
|
|
|
|
// These overrides replace OS-level system install paths in tests. There is
|
|
// intentionally no env var or flag for them.
|
|
var (
|
|
systemBinDirOverride string
|
|
systemProfilePathOverride string
|
|
// systemExecutableOwnershipCheck requires root ownership of the binary and
|
|
// its parent directories. Disabled in tests that cannot create root-owned files.
|
|
systemExecutableOwnershipCheck = true
|
|
)
|
|
|
|
// SystemBinDir returns the directory for system-wide PMG shims.
|
|
func SystemBinDir() string {
|
|
if systemBinDirOverride != "" {
|
|
return systemBinDirOverride
|
|
}
|
|
return defaultSystemBinDir
|
|
}
|
|
|
|
// SystemProfilePath returns the path of the system profile.d snippet.
|
|
func SystemProfilePath() string {
|
|
if systemProfilePathOverride != "" {
|
|
return systemProfilePathOverride
|
|
}
|
|
return defaultSystemProfilePath
|
|
}
|
|
|
|
// NewSystemShimManager creates a shim manager for system-wide install: shims
|
|
// under SystemBinDir, no per-user rc edits, and /etc/profile.d management.
|
|
// The current executable is validated for multi-user use.
|
|
func NewSystemShimManager() (*ShimManager, error) {
|
|
return newSystemShimManager(true)
|
|
}
|
|
|
|
// NewSystemShimManagerForRemove creates a system shim manager without
|
|
// validating the current executable. Uninstall must work even when the binary
|
|
// that originally installed the shims is no longer suitable for install.
|
|
func NewSystemShimManagerForRemove() (*ShimManager, error) {
|
|
return newSystemShimManager(false)
|
|
}
|
|
|
|
func newSystemShimManager(validateExecutable bool) (*ShimManager, error) {
|
|
aliasCfg := alias.DefaultConfig()
|
|
pmgBin, err := currentExecutable()
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
if validateExecutable {
|
|
if err := validateSystemExecutable(pmgBin); err != nil {
|
|
return nil, err
|
|
}
|
|
}
|
|
|
|
return &ShimManager{
|
|
config: ShimConfig{
|
|
BinDir: SystemBinDir(),
|
|
PMGBin: pmgBin,
|
|
PackageManagers: aliasCfg.PackageManagers,
|
|
SkipShellRc: true,
|
|
ManageProfile: true,
|
|
},
|
|
}, nil
|
|
}
|
|
|
|
// validateSystemExecutable rejects binaries unsafe for system-wide shims.
|
|
// System shims hard-code this path, so it must be world-executable, not
|
|
// group/other-writable, and (when ownership checks are enabled) root-owned
|
|
// under a root-owned, non-group/other-writable directory chain.
|
|
func validateSystemExecutable(path string) error {
|
|
info, err := os.Stat(path)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to inspect pmg executable %s: %w", path, err)
|
|
}
|
|
|
|
perm := info.Mode().Perm()
|
|
if perm&0o001 == 0 {
|
|
return fmt.Errorf("pmg executable %s is not executable by all users", path)
|
|
}
|
|
if perm&0o022 != 0 {
|
|
return fmt.Errorf("pmg executable %s is writable by group or others", path)
|
|
}
|
|
|
|
if systemExecutableOwnershipCheck {
|
|
if err := requireRootOwnedPath(path, info); err != nil {
|
|
return err
|
|
}
|
|
if err := requireSafeAncestorDirs(filepath.Dir(path)); err != nil {
|
|
return err
|
|
}
|
|
}
|
|
return nil
|
|
}
|
|
|
|
func requireRootOwnedPath(path string, info os.FileInfo) error {
|
|
uid, ok := fileOwnerUID(info)
|
|
if !ok {
|
|
return fmt.Errorf("cannot determine owner of %s", path)
|
|
}
|
|
if uid != 0 {
|
|
return fmt.Errorf("pmg executable %s must be owned by root", path)
|
|
}
|
|
return nil
|
|
}
|
|
|
|
func requireSafeAncestorDirs(dir string) error {
|
|
for {
|
|
info, err := os.Stat(dir)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to inspect directory %s: %w", dir, err)
|
|
}
|
|
if info.Mode().Perm()&0o022 != 0 {
|
|
return fmt.Errorf("directory %s on pmg executable path is writable by group or others", dir)
|
|
}
|
|
uid, ok := fileOwnerUID(info)
|
|
if !ok {
|
|
return fmt.Errorf("cannot determine owner of directory %s", dir)
|
|
}
|
|
if uid != 0 {
|
|
return fmt.Errorf("directory %s on pmg executable path must be owned by root", dir)
|
|
}
|
|
parent := filepath.Dir(dir)
|
|
if parent == dir {
|
|
return nil
|
|
}
|
|
dir = parent
|
|
}
|
|
}
|
|
|
|
// SystemShimsInstalled reports whether the system shim directory contains at
|
|
// least one shim script.
|
|
func SystemShimsInstalled() bool {
|
|
return shimsPresent(SystemBinDir())
|
|
}
|
|
|
|
func shimsPresent(dir string) bool {
|
|
entries, err := os.ReadDir(dir)
|
|
if err != nil {
|
|
return false
|
|
}
|
|
for _, e := range entries {
|
|
if e.IsDir() {
|
|
continue
|
|
}
|
|
content, err := os.ReadFile(filepath.Join(dir, e.Name()))
|
|
if err == nil && strings.Contains(string(content), shimScriptMarker) {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|
|
|
|
// SystemProfileInstalled reports whether the system profile snippet exists and
|
|
// contains the PMG marker.
|
|
func SystemProfileInstalled() bool {
|
|
data, err := os.ReadFile(SystemProfilePath())
|
|
if err != nil {
|
|
return false
|
|
}
|
|
return strings.Contains(string(data), systemProfileMarker)
|
|
}
|
|
|
|
func writeSystemProfile(binDir string) error {
|
|
path := SystemProfilePath()
|
|
|
|
if err := os.MkdirAll(filepath.Dir(path), 0o755); err != nil {
|
|
return fmt.Errorf("failed to create profile.d directory: %w", err)
|
|
}
|
|
|
|
content := fmt.Sprintf(`# %s - managed by pmg setup install --system
|
|
# remove by running: pmg setup remove --system
|
|
export PATH="%s:$PATH"
|
|
`, systemProfileMarker, binDir)
|
|
|
|
data, err := os.ReadFile(path)
|
|
if err == nil && string(data) == content {
|
|
return nil
|
|
}
|
|
|
|
if err != nil && !os.IsNotExist(err) {
|
|
return fmt.Errorf("failed to read system profile %s: %w", path, err)
|
|
}
|
|
|
|
if err := os.WriteFile(path, []byte(content), 0o644); err != nil {
|
|
return fmt.Errorf("failed to write system profile %s: %w", path, err)
|
|
}
|
|
return nil
|
|
}
|
|
|
|
func removeSystemProfile() error {
|
|
path := SystemProfilePath()
|
|
if err := os.Remove(path); err != nil && !os.IsNotExist(err) {
|
|
return fmt.Errorf("failed to remove system profile %s: %w", path, err)
|
|
}
|
|
return nil
|
|
}
|