LibrePortal/scripts/function/folder/create_folder.sh
librelad 75dfb3849b fix(rootless): backup/ssh WebUI generators write as the container owner
The backup + ssh generators created their frontend/data dirs via plain/sudo
mkdir and wrote files via sudo tee/mv (root-owned), then called createTouch
(dockerinstall) which can't re-own a root file — so every write hit
'touch: Permission denied' in rootless and left root-owned data the
dockerinstall container/generators can't rewrite. Convert dir creation to
runFileOp mkdir and file writes to runFileWrite (both run as the container
owner: dockerinstall in rootless, manager in rooted), dropping the
temp/mv/createTouch dance. Also make the createFolders chokepoint mode-aware
(containers/ paths created via runFileOp) so it mirrors createTouch.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Signed-off-by: librelad <librelad@digitalangels.vip>
2026-05-24 14:04:06 +01:00

44 lines
1.6 KiB
Bash
Executable File

#!/bin/bash
createFolders()
{
local silent_flag="$1"
local user_name="$2"
for dir_path in "${@:3}"; do
local folder_name=$(basename "$dir_path")
local clean_dir=$(echo "$dir_path" | sed 's#//*#/#g')
# Under /docker/containers/<app>/ the owner is the docker install user
# (the rootless container + host generators run as it), so create the dir
# AS that user via runFileOp — creating it as the right owner avoids a
# chown-to-another-user the unprivileged runtime can't do. Mirrors
# createTouch; the $user_name hint is advisory for these paths.
if [[ "$clean_dir" == "$containers_dir"* || "$clean_dir" == /docker/containers/* ]]; then
if [ ! -d "$dir_path" ]; then
local result=$(runFileOp mkdir -p "$dir_path")
[ "$silent_flag" == "loud" ] && checkSuccess "Creating $folder_name directory"
elif [ "$silent_flag" == "loud" ]; then
isNotice "$folder_name directory already exists"
fi
continue
fi
if [ ! -d "$dir_path" ]; then
local result=$(sudo mkdir -p "$dir_path")
if [ "$silent_flag" == "loud" ]; then
checkSuccess "Creating $folder_name directory"
fi
else
if [ "$silent_flag" == "loud" ]; then
isNotice "$folder_name directory already exists"
fi
fi
local result=$(sudo chown $user_name:$user_name "$dir_path")
if [ "$silent_flag" == "loud" ]; then
checkSuccess "Updating $folder_name with $user_name ownership"
fi
done
}