2 Commits

Author SHA1 Message Date
urania b10abb24e3 fix: various
build-and-release / release (push) Successful in 2m49s
2026-06-22 22:40:34 +02:00
urania 9587d11e21 fix: localectl
build-and-release / release (push) Successful in 2m38s
2026-06-22 22:22:36 +02:00
6 changed files with 97 additions and 39 deletions
+1 -2
View File
@@ -239,8 +239,7 @@ func runServer() {
meta.Register(api, mods)
meta.RegisterHealth(api, sessions)
meta.RegisterWhoami(api, sessions, roles, mods)
meta.ConfigPath = configPath
meta.RegisterUpdate(api)
meta.RegisterUpdate(api, configPath)
auth.RegisterLogin(api, sessions, auditStore, cfg.SecureCookie())
auth.RegisterLogout(api, sessions, cfg.SecureCookie())
+3 -2
View File
@@ -1,8 +1,9 @@
package main
import (
"crypto/ecdsa"
"crypto/elliptic"
"crypto/rand"
"crypto/rsa"
"crypto/tls"
"crypto/x509"
"crypto/x509/pkix"
@@ -24,7 +25,7 @@ func serverCert(certPath, keyPath string) (tls.Certificate, error) {
}
func generateSelfSignedCert() (tls.Certificate, error) {
priv, err := rsa.GenerateKey(rand.Reader, 2048)
priv, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
if err != nil {
return tls.Certificate{}, err
}
+15 -3
View File
@@ -110,13 +110,25 @@ func Load(path string) (*File, error) {
return nil, fmt.Errorf("parse config %s: %w", path, err)
}
// release_repo, when set, is downloaded over the wire and (for /api/update)
// executed. Reject http:// at the boundary so /install.sh and the updater
// never have to re-check.
// executed. Validate shape + scheme once here so /install.sh and the updater
// can use the string directly. Trim any trailing slash so downstream string
// concatenation produces a clean URL.
if f.Server.ReleaseRepo != "" {
f.Server.ReleaseRepo = strings.TrimRight(f.Server.ReleaseRepo, "/")
u, err := url.Parse(f.Server.ReleaseRepo)
if err != nil || u.Scheme != "https" {
if err != nil {
return nil, fmt.Errorf("server.release_repo: %w", err)
}
if u.Scheme != "https" {
return nil, fmt.Errorf("server.release_repo must use https:// (got %q)", f.Server.ReleaseRepo)
}
if u.Host == "" {
return nil, fmt.Errorf("server.release_repo missing host: %q", f.Server.ReleaseRepo)
}
parts := strings.Split(strings.Trim(u.Path, "/"), "/")
if len(parts) != 2 || parts[0] == "" || parts[1] == "" {
return nil, fmt.Errorf("server.release_repo must be https://host/owner/repo, got %q", f.Server.ReleaseRepo)
}
}
return &f, nil
}
+8 -9
View File
@@ -12,19 +12,18 @@ import (
"github.com/danielgtaylor/huma/v2"
)
// ConfigPath is set at startup so the update handler can re-load config and
// surface release_repo / parse errors to the caller instead of only stderr.
var ConfigPath string
// RegisterUpdate wires POST /api/meta/update. It runs the equivalent of
// RegisterUpdate wires POST /api/update. It runs the equivalent of
// `sudo nadir update` in a detached session and returns 202 immediately; the
// systemctl restart that ends the updater drops in-flight connections, so the
// caller should poll /api/health to confirm the new version is up.
//
// configPath is re-read by the handler so a missing release_repo (or any other
// config error) surfaces as 4xx/5xx to the caller, not as stderr only.
//
// Authorization: requires (meta, root). Only roles with a wildcard grant
// (the default admin role) match, since "meta" isn't a real module with a
// declared permission vocabulary.
func RegisterUpdate(api huma.API) {
func RegisterUpdate(api huma.API, configPath string) {
huma.Register(api, huma.Operation{
OperationID: "meta-update",
Method: "POST",
@@ -36,13 +35,13 @@ func RegisterUpdate(api huma.API) {
Errors: []int{400, 401, 403, 500},
DefaultStatus: 202,
}, func(ctx context.Context, _ *struct{}) (*oscmd.StatusOutput, error) {
if ConfigPath != "" {
cfg, err := config.Load(ConfigPath)
if configPath != "" {
cfg, err := config.Load(configPath)
if err != nil {
return nil, huma.Error500InternalServerError("config load failed", err)
}
if cfg.Server.ReleaseRepo == "" {
return nil, huma.Error400BadRequest("server.release_repo not set in " + ConfigPath)
return nil, huma.Error400BadRequest("server.release_repo not set in " + configPath)
}
}
exe, err := os.Executable()
+53 -20
View File
@@ -16,6 +16,7 @@ import (
type LocaleStatusBody struct {
Lang string `json:"lang" example:"it_IT.UTF-8" doc:"System locale (LANG)"`
Language string `json:"language" example:"en_US:" doc:"Fallback language list (LANGUAGE)"`
VCKeymap string `json:"vc_keymap" example:"it" doc:"Virtual console keymap"`
X11Layout string `json:"x11_layout" example:"it" doc:"X11 keyboard layout"`
}
@@ -31,12 +32,14 @@ type LocalesOutput struct {
type KeymapsOutput struct {
Body struct {
Keymaps []string `json:"keymaps" doc:"Available virtual console keymaps"`
Reason string `json:"reason,omitempty" doc:"When keymaps is empty, why: e.g. \"kbd not installed on this server\""`
}
}
type SetLocaleInput struct {
Body struct {
Lang string `json:"lang" example:"it_IT.UTF-8" doc:"Locale to set as LANG"`
Language *string `json:"language,omitempty" example:"en_US:" doc:"Fallback language list (LANGUAGE)"`
}
}
@@ -56,6 +59,10 @@ type GenerateLocaleInput struct {
// .charmap suffix (e.g. fr_FR, fr_FR.UTF-8, en_US.ISO-8859-1).
var localeRe = regexp.MustCompile(`^[a-z]{2,3}_[A-Z]{2}(\.[A-Za-z0-9_-]+)?$`)
// languageRe validates the LANGUAGE fallback list: colon-separated locale names
// like "en_US:de_DE". Anchored so a leading "-" can't survive into argv.
var languageRe = regexp.MustCompile(`^[a-zA-Z0-9_.:-]*$`)
func localeStatus() (LocaleStatusBody, error) {
lines, err := oscmd.RunLines("localectl", "status")
if err != nil {
@@ -63,21 +70,28 @@ func localeStatus() (LocaleStatusBody, error) {
}
var b LocaleStatusBody
for _, line := range lines {
label, val, ok := strings.Cut(line, ":")
if !ok {
trimmed := strings.TrimSpace(line)
if strings.HasPrefix(trimmed, "VC Keymap:") {
b.VCKeymap = strings.TrimSpace(strings.TrimPrefix(trimmed, "VC Keymap:"))
continue
}
switch strings.TrimSpace(label) {
case "System Locale":
for kv := range strings.FieldsSeq(val) {
if k, v, ok := strings.Cut(kv, "="); ok && k == "LANG" {
if strings.HasPrefix(trimmed, "X11 Layout:") {
b.X11Layout = strings.TrimSpace(strings.TrimPrefix(trimmed, "X11 Layout:"))
continue
}
// Parse k=v fields on any other line (like System Locale block).
parts := strings.Fields(trimmed)
for _, part := range parts {
part = strings.TrimPrefix(part, "System Locale:")
part = strings.TrimSpace(part)
if k, v, ok := strings.Cut(part, "="); ok {
switch k {
case "LANG":
b.Lang = v
case "LANGUAGE":
b.Language = v
}
}
case "VC Keymap":
b.VCKeymap = strings.TrimSpace(val)
case "X11 Layout":
b.X11Layout = strings.TrimSpace(val)
}
}
return b, nil
@@ -144,7 +158,17 @@ func registerLocale(api huma.API) {
if !slices.Contains(locales, lang) {
return nil, huma.Error400BadRequest("unknown locale: " + lang)
}
if _, err := oscmd.Run("localectl", "set-locale", "LANG="+lang); err != nil {
args := []string{"set-locale", "LANG=" + lang}
if in.Body.Language != nil {
langVal := strings.TrimSpace(*in.Body.Language)
if !languageRe.MatchString(langVal) {
return nil, huma.Error400BadRequest("invalid language format: " + langVal)
}
args = append(args, "LANGUAGE="+langVal)
}
if _, err := oscmd.Run("localectl", args...); err != nil {
return nil, huma.Error500InternalServerError("set-locale failed", err)
}
return oscmd.OK(), nil
@@ -160,12 +184,15 @@ func registerLocale(api huma.API) {
Metadata: op("read"),
Errors: readErrors,
}, func(ctx context.Context, _ *struct{}) (*KeymapsOutput, error) {
// ponytail: minimal servers ship without kbd / /usr/share/keymaps, so
// localectl errors instead of returning empty. Surface that as a `reason`
// the frontend can display ("kbd not installed") instead of an opaque N/A.
keymaps, err := oscmd.RunLines("localectl", "list-keymaps")
if err != nil {
return nil, huma.Error500InternalServerError("localectl failed", err)
}
out := &KeymapsOutput{}
out.Body.Keymaps = keymaps
if err != nil || len(keymaps) == 0 {
out.Body.Reason = "kbd is not installed on this server (install the kbd / console-data package to enable keymap selection)"
}
return out, nil
})
@@ -185,10 +212,9 @@ func registerLocale(api huma.API) {
if km == "" {
return nil, huma.Error400BadRequest("empty keymap")
}
keymaps, err := oscmd.RunLines("localectl", "list-keymaps")
if err != nil {
return nil, huma.Error500InternalServerError("localectl failed", err)
}
// list-keymaps failure means no keymap allowlist on this host (kbd absent);
// fall through to unknown-keymap 400 instead of 500.
keymaps, _ := oscmd.RunLines("localectl", "list-keymaps")
if !slices.Contains(keymaps, km) {
return nil, huma.Error400BadRequest("unknown keymap: " + km)
}
@@ -209,7 +235,7 @@ func registerLocale(api huma.API) {
"already generated, returns 200 immediately.",
Tags: []string{tagSystem},
Metadata: op("write"),
Errors: append(writeErrors, 501),
Errors: []int{400, 401, 403, 500, 501},
}, func(ctx context.Context, in *GenerateLocaleInput) (*oscmd.StatusOutput, error) {
locale := strings.TrimSpace(in.Body.Locale)
if locale == "" {
@@ -263,9 +289,16 @@ func enableLocaleGen(path, locale string) error {
if !found {
return huma.Error400BadRequest("locale not available for generation: " + locale)
}
if err := os.WriteFile(path, []byte(newContent), 0644); err != nil {
// Write atomically: a crash mid-write would leave /etc/locale.gen truncated
// and break every subsequent locale-gen on the host.
tmp := path + ".nadir.tmp"
if err := os.WriteFile(tmp, []byte(newContent), 0644); err != nil {
return huma.Error500InternalServerError("writing locale.gen failed", err)
}
if err := os.Rename(tmp, path); err != nil {
os.Remove(tmp)
return huma.Error500InternalServerError("replacing locale.gen failed", err)
}
if _, err := oscmd.Run("locale-gen"); err != nil {
return huma.Error500InternalServerError("locale-gen failed", err)
}
+16 -2
View File
@@ -142,7 +142,7 @@ func TestSystemHandlers(t *testing.T) {
// 4. Test GET & POST /api/system/locale
oscmd.SetMock("localectl", func(args []string) oscmd.MockCommand {
if reflect.DeepEqual(args, []string{"status"}) {
statusOut := " System Locale: LANG=it_IT.UTF-8\n VC Keymap: it\n X11 Layout: it\n"
statusOut := " System Locale: LANG=it_IT.UTF-8\n LANGUAGE=en_US:\n VC Keymap: it\n X11 Layout: it\n"
return oscmd.MockCommand{Stdout: statusOut, ExitCode: 0}
}
if reflect.DeepEqual(args, []string{"list-locales"}) {
@@ -151,6 +151,9 @@ func TestSystemHandlers(t *testing.T) {
if reflect.DeepEqual(args, []string{"set-locale", "LANG=it_IT.UTF-8"}) {
return oscmd.MockCommand{ExitCode: 0}
}
if reflect.DeepEqual(args, []string{"set-locale", "LANG=it_IT.UTF-8", "LANGUAGE=en_US:"}) {
return oscmd.MockCommand{ExitCode: 0}
}
if reflect.DeepEqual(args, []string{"list-keymaps"}) {
return oscmd.MockCommand{Stdout: "it\nus\n", ExitCode: 0}
}
@@ -168,7 +171,7 @@ func TestSystemHandlers(t *testing.T) {
if err := json.Unmarshal(resp.Body.Bytes(), &localeRes.Body); err != nil {
t.Fatal(err)
}
if localeRes.Body.Lang != "it_IT.UTF-8" || localeRes.Body.VCKeymap != "it" {
if localeRes.Body.Lang != "it_IT.UTF-8" || localeRes.Body.Language != "en_US:" || localeRes.Body.VCKeymap != "it" {
t.Errorf("got locale status: %+v", localeRes.Body)
}
@@ -186,6 +189,17 @@ func TestSystemHandlers(t *testing.T) {
t.Errorf("set locale: got %d, want %d", resp.Code, http.StatusOK)
}
resp = api.Post("/api/system/locale", struct {
Lang string `json:"lang"`
Language string `json:"language"`
}{
Lang: "it_IT.UTF-8",
Language: "en_US:",
})
if resp.Code != http.StatusOK {
t.Errorf("set locale with language: got %d, want %d", resp.Code, http.StatusOK)
}
resp = api.Get("/api/system/keymaps")
if resp.Code != http.StatusOK {
t.Errorf("list keymaps: got %d, want %d", resp.Code, http.StatusOK)