mirror of
https://github.com/PegaProx/project-pegaprox.git
synced 2026-08-12 15:27:47 +08:00
Reported by @tgmct: every fresh v0.9.10 install where deploy.sh runs Step 5
(master-key bootstrap) results in pegaprox.service failing to start with
`PermissionError: [Errno 13] Permission denied: '/etc/pegaprox/secret.key'`.
Root cause: deploy.sh Step 5 wrote /etc/pegaprox/secret.key with mode
0600 root:pegaprox. The systemd unit runs as the `pegaprox` service user.
Owner is root, group is pegaprox, but mode 0600 grants read only to the
*owner* — the service user (a group member, not the owner) cannot read
its own master key. So every fresh install boot-loops.
Three-part fix:
(1) deploy.sh Step 5: master key now created at 0640 root:$SERVICE_GROUP
(group-readable so the service can load it). Key directory is now
0750 to match.
(2) deploy.sh Step 5: existing v0.9.10 / v0.9.10.1 / v0.9.10.2 installs
self-heal on the next `update.sh` — if /etc/pegaprox/secret.key is
found at mode 0600 or 0400, deploy.sh bumps it to 0640 and logs a
`(#417 repair)` print_info. A key already at 0640 / 0440 is left
untouched.
(3) pegaprox/core/keystore.py `_enforce_perms` was relaxed from "must be
0600" to "must be 0600 OR 0640". Anything with group-write,
group-exec, or any other-perm bit set is still rejected hard — the
function raises RuntimeError, not silent skip, so an accidentally
world-readable key never becomes the active key.
Hard rejection mask is now exactly `S_IWGRP | S_IXGRP | S_IRWXO`.
Accepted modes: 0600, 0400, 0640, 0440. Verified with 8-case unit pass.
docs/SECURITY.md tier table updated: Tier 4 row now states "chmod 0640
root:pegaprox — group-read required" and explains why 0600 root:pegaprox
is unreadable for the service. The "loose-perms" paragraph corrected
from "skipped" to "rejected" (matches the actual code behaviour).
Workaround for existing installs that hit the bug *before* this update
can be applied (i.e. operators stuck at boot-loop on v0.9.10/.1/.2):
sudo chmod 640 /etc/pegaprox/secret.key
sudo systemctl restart pegaprox
Files touched:
- deploy.sh (Step 5: 3x chmod 600 -> 640, dir 700 -> 750, repair-on-upgrade)
- pegaprox/core/keystore.py (_enforce_perms accepts S_IRGRP; docstring)
- docs/SECURITY.md (tier table + loader rejection wording)
- version.json, pegaprox/constants.py, web/src/constants.js, README.md
(version bump to 0.9.10.3 / build 2026.05.15)
- web/index.html (frontend rebuild for new version constant)