mirror of
https://github.com/versity/versitygw.git
synced 2026-09-07 08:36:54 +00:00
feat: add --socket-perm option for UNIX socket file permissions
Add a --socket-perm flag (VGW_SOCKET_PERM env var) to control the file-mode permissions on file-backed UNIX domain sockets. This allows operators to limit access permission without relying on process umask. The option applies to S3, admin, and WebUI sockets and has no effect on TCP/IP addresses or Linux abstract namespace sockets. Fixes #2010
This commit is contained in:
@@ -105,6 +105,7 @@ var (
|
||||
disableACLs bool
|
||||
mpMaxParts int
|
||||
copyObjectThreshold int64
|
||||
socketPerm string
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -772,6 +773,12 @@ func initFlags() []cli.Flag {
|
||||
Value: 5 * 1024 * 1024 * 1024,
|
||||
Destination: ©ObjectThreshold,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "socket-perm",
|
||||
Usage: "file permissions for file-backed UNIX domain sockets (octal, e.g. '0660'); ignored for TCP/IP and abstract namespace sockets",
|
||||
EnvVars: []string{"VGW_SOCKET_PERM"},
|
||||
Destination: &socketPerm,
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
@@ -855,6 +862,15 @@ func runGateway(ctx context.Context, be backend.Backend) error {
|
||||
|
||||
utils.SetBucketNameValidationStrict(!disableStrictBucketNames)
|
||||
|
||||
var parsedSocketPerm os.FileMode
|
||||
if socketPerm != "" {
|
||||
perm, err := strconv.ParseUint(socketPerm, 8, 32)
|
||||
if err != nil {
|
||||
return fmt.Errorf("invalid --socket-perm value %q: must be an octal integer (e.g. '0660'): %w", socketPerm, err)
|
||||
}
|
||||
parsedSocketPerm = os.FileMode(perm)
|
||||
}
|
||||
|
||||
if pprof != "" {
|
||||
// listen on specified port for pprof debug
|
||||
// point browser to http://<ip:port>/debug/pprof/
|
||||
@@ -867,6 +883,9 @@ func runGateway(ctx context.Context, be backend.Backend) error {
|
||||
s3api.WithConcurrencyLimiter(maxConnections, maxRequests),
|
||||
s3api.WithMpMaxParts(mpMaxParts),
|
||||
}
|
||||
if socketPerm != "" {
|
||||
opts = append(opts, s3api.WithSocketPerm(parsedSocketPerm))
|
||||
}
|
||||
if corsAllowOrigin != "" {
|
||||
opts = append(opts, s3api.WithCORSAllowOrigin(corsAllowOrigin))
|
||||
}
|
||||
@@ -1103,6 +1122,9 @@ func runGateway(ctx context.Context, be backend.Backend) error {
|
||||
if debug {
|
||||
opts = append(opts, s3api.WithAdminDebug())
|
||||
}
|
||||
if socketPerm != "" {
|
||||
opts = append(opts, s3api.WithAdminSocketPerm(parsedSocketPerm))
|
||||
}
|
||||
|
||||
admSrv = s3api.NewAdminServer(be, middlewares.RootUserConfig{Access: rootUserAccess, Secret: rootUserSecret}, region, iam, loggers.AdminLogger, srv.Router.Ctrl, opts...)
|
||||
}
|
||||
@@ -1215,6 +1237,9 @@ func runGateway(ctx context.Context, be backend.Backend) error {
|
||||
if webuiPathPrefix != "" {
|
||||
webOpts = append(webOpts, webui.WithPathPrefix(webuiPathPrefix))
|
||||
}
|
||||
if socketPerm != "" {
|
||||
webOpts = append(webOpts, webui.WithSocketPerm(parsedSocketPerm))
|
||||
}
|
||||
|
||||
webSrv = webui.NewServer(&webui.ServerConfig{
|
||||
Gateways: gateways,
|
||||
|
||||
Reference in New Issue
Block a user