after moving all to cipher
This commit is contained in:
@@ -34,9 +34,16 @@ export function resolveWorkspaceOwner(ownerRef: string): { uid: number; gid: num
|
||||
}
|
||||
}
|
||||
|
||||
/** Owner-rwX mode, preserving every other bit. Dirs also need the search bit. */
|
||||
function withOwnerAccess(mode: number, isDir: boolean): number {
|
||||
return mode | (isDir ? 0o700 : 0o600);
|
||||
/**
|
||||
* Owner-rwX mode, preserving every other bit. Dirs also need the search bit.
|
||||
*
|
||||
* `stranded` means the file stays root-owned because we have no non-root owner to
|
||||
* give it to. Owner bits then help nobody — whoever has to read it is a different
|
||||
* user — so read and search are granted more widely. Never write, never +x on files.
|
||||
*/
|
||||
function withOwnerAccess(mode: number, isDir: boolean, stranded: boolean): number {
|
||||
const owner = isDir ? 0o700 : 0o600;
|
||||
return mode | owner | (stranded ? (isDir ? 0o055 : 0o044) : 0);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -75,7 +82,7 @@ export function normalizeTreePermissions(
|
||||
const isDir = st.isDirectory();
|
||||
|
||||
// Mode first: a directory we can't search is one we can't descend into.
|
||||
const wanted = withOwnerAccess(st.mode, isDir);
|
||||
const wanted = withOwnerAccess(st.mode, isDir, chownTarget === null && st.uid === 0);
|
||||
if (wanted !== st.mode) {
|
||||
try {
|
||||
chmodSync(path, wanted);
|
||||
|
||||
Reference in New Issue
Block a user