From 457351fa0b3a602d545b63f1de7169efbb0dd3cb Mon Sep 17 00:00:00 2001 From: CaliBrain Date: Sun, 27 Apr 2025 13:49:07 -0400 Subject: [PATCH] Better File check (#165) - Better file permission initialization - Fix chown bug --- Dockerfile | 4 ---- backend.py | 18 +++++++----------- entrypoint.sh | 51 +++++++++++++++++++++++++++++++++++++++++++++------ 3 files changed, 52 insertions(+), 21 deletions(-) diff --git a/Dockerfile b/Dockerfile index 2e61762a..6cce8f95 100644 --- a/Dockerfile +++ b/Dockerfile @@ -66,7 +66,6 @@ WORKDIR /app # Install Python dependencies using pip # Upgrade pip first, then copy requirements and install # Copying requirements.txt separately leverages build cache -# No --chown needed as it's copied as root COPY requirements.txt . RUN pip install --no-cache-dir -r requirements.txt && \ # Clean root's pip cache @@ -84,7 +83,6 @@ RUN echo "#!/bin/sh" > /usr/local/bin/pyrequests && \ chmod +x /usr/local/bin/pyrequests # Copy application code *after* dependencies are installed -# No --chown needed as it's copied as root, entrypoint will handle permissions COPY . . # Final setup: permissions and directories in one layer @@ -92,8 +90,6 @@ COPY . . # Ownership will be handled by the entrypoint script. RUN mkdir -p /var/log/cwa-book-downloader /cwa-book-ingest && \ chmod +x /app/entrypoint.sh /app/tor.sh /app/genDebug.sh - # chown is removed - # Expose the application port EXPOSE ${FLASK_PORT} diff --git a/backend.py b/backend.py index 941fa1f2..20578669 100644 --- a/backend.py +++ b/backend.py @@ -8,7 +8,7 @@ import subprocess import os from logger import setup_logger -from config import CUSTOM_SCRIPT, CROSS_FILE_SYSTEM +from config import CUSTOM_SCRIPT from env import INGEST_DIR, TMP_DIR, MAIN_LOOP_SLEEP_TIME, USE_BOOK_TITLE from models import book_queue, BookInfo, QueueStatus, SearchFilters import book_manager @@ -141,17 +141,13 @@ def _download_book(book_id: str) -> Optional[str]: final_path = INGEST_DIR / book_name if os.path.exists(book_path): - if CROSS_FILE_SYSTEM: - logger.info(f"Copying book to ingest directory then renaming: {book_path} -> {intermediate_path} -> {final_path}") - try: - shutil.move(book_path, intermediate_path) - except Exception as e: - logger.debug(f"Error moving book: {e}, will try copying instead") - shutil.copy(book_path, intermediate_path) - os.remove(book_path) - else: - logger.info(f"Moving book to ingest directory: {book_path} -> {intermediate_path}") + logger.info(f"Moving book to ingest directory then renaming: {book_path} -> {intermediate_path} -> {final_path}") + try: shutil.move(book_path, intermediate_path) + except Exception as e: + logger.debug(f"Error moving book: {e}, will try copying instead") + shutil.copy(book_path, intermediate_path) + os.remove(book_path) logger.info(f"Renaming book: {intermediate_path} -> {final_path}") os.rename(intermediate_path, final_path) return str(final_path) diff --git a/entrypoint.sh b/entrypoint.sh index 545d1b57..29c63f03 100644 --- a/entrypoint.sh +++ b/entrypoint.sh @@ -6,11 +6,10 @@ LOG_FILE=${LOG_DIR}/cwa-bd_entrypoint.log # Cleanup any existing files or folders in the log directory rm -rf $LOG_DIR/* - ( -if [ "$USING_TOR" = "true" ]; then - ./tor.sh -fi + if [ "$USING_TOR" = "true" ]; then + ./tor.sh + fi ) exec 3>&1 4>&2 @@ -52,18 +51,58 @@ fi # Get username for the UID (whether we just created it or it existed) USERNAME=$(getent passwd "$UID" | cut -d: -f1) echo "Username for UID $UID is $USERNAME" + +test_write() { + folder=$1 + test_file=$folder/calibre-web-automated-book-downloader_TEST_WRITE + mkdir -p $folder + ( + echo 0123456789_TEST | sudo -E -u "$USERNAME" HOME=/app tee $test_file > /dev/null + ) + FILE_CONTENT=$(cat $test_file || echo "") + rm -f $test_file + [ "$FILE_CONTENT" = "0123456789_TEST" ] + result=$? + if [ $result -eq 0 ]; then + result_text="true" + else + result_text="false" + fi + echo "Test write to $folder by $USERNAME: $result_text" + return $result +} + +make_writable() { + folder=$1 + set +e + is_writable=$(test_write $folder) + set -e + if [ "$is_writable" = "true" ]; then + echo "Folder $folder is writable, no need to change ownership" + else + echo "Folder $folder is not writable, changing ownership" + change_ownership $folder + chmod g+r,g+w $folder + fi + test_write $folder +} + # Ensure proper ownership of application directories change_ownership() { folder=$1 + mkdir -p $folder echo "Changing ownership of $folder to $USERNAME:$GID" - chown -R "${UID}:${GID}" "${folder}" || echo "Failed to change ownership for ${folder}, continuing..." + chown -R "${UID}" "${folder}" || echo "Failed to change user ownership for ${folder}, continuing..." + chown -R ":${GID}" "${folder}" || echo "Failed to change group ownership for ${folder}, continuing..." } change_ownership /app change_ownership /var/log/cwa-book-downloader -change_ownership /cwa-book-ingest change_ownership /tmp/cwa-book-downloader +# Test write to all folders +make_writable /cwa-book-ingest + # Set the command to run based on the environment is_prod=$(echo "$APP_ENV" | tr '[:upper:]' '[:lower:]') if [ "$is_prod" = "prod" ]; then