Sanitized root snapshot from private source commit a72903c63e1753f9e6ffbf40453c0830bdfc05c5 and tree 295641e67eef5979da76746d8ae271249568263e. Private development history and workflows are excluded by the exact allowlist. AI-assisted: OpenAI Codex helped implement, test, and audit this preview. Signed-off-by: Cole Speelman <crspeelman@gmail.com>
39 lines
743 B
Go
39 lines
743 B
Go
//go:build linux
|
|
|
|
// SPDX-License-Identifier: AGPL-3.0-only
|
|
|
|
package deploy
|
|
|
|
import (
|
|
"os"
|
|
"syscall"
|
|
)
|
|
|
|
type fileIdentity struct {
|
|
mode os.FileMode
|
|
uid, gid int
|
|
owned bool
|
|
}
|
|
|
|
func identityFor(info os.FileInfo, fallback os.FileMode) fileIdentity {
|
|
identity := fileIdentity{mode: fallback}
|
|
if info == nil {
|
|
return identity
|
|
}
|
|
identity.mode = info.Mode().Perm()
|
|
if stat, ok := info.Sys().(*syscall.Stat_t); ok {
|
|
identity.uid = int(stat.Uid)
|
|
identity.gid = int(stat.Gid)
|
|
identity.owned = true
|
|
}
|
|
return identity
|
|
}
|
|
func applyIdentity(file *os.File, identity fileIdentity) error {
|
|
if identity.owned {
|
|
if err := file.Chown(identity.uid, identity.gid); err != nil {
|
|
return err
|
|
}
|
|
}
|
|
return file.Chmod(identity.mode)
|
|
}
|