Compare commits
15 Commits
0.1.0
...
4a4cb8183f
| Author | SHA1 | Date | |
|---|---|---|---|
| 4a4cb8183f | |||
|
20a0dca080
|
|||
|
7c391b8dbc
|
|||
| aafad81bb6 | |||
|
9658f534ea
|
|||
|
5af28d21ca
|
|||
| b0395a432f | |||
|
603e2ac0c6
|
|||
| 9c915576e9 | |||
|
96970b6963
|
|||
|
5353310e15
|
|||
|
e8f63386bb
|
|||
|
e0ec2ce60a
|
|||
|
a5551e7047
|
|||
|
4b67e721e7
|
1
.gitea/CODEOWNERS
Normal file
1
.gitea/CODEOWNERS
Normal file
@@ -0,0 +1 @@
|
|||||||
|
* @mdaleo404
|
||||||
36
.gitea/workflows/lint-and-security.yml
Normal file
36
.gitea/workflows/lint-and-security.yml
Normal file
@@ -0,0 +1,36 @@
|
|||||||
|
name: Lint & Security
|
||||||
|
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
precommit-and-security:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Checkout code
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Set up Python
|
||||||
|
uses: actions/setup-python@v5
|
||||||
|
with:
|
||||||
|
python-version: "3.13"
|
||||||
|
|
||||||
|
- name: Install pre-commit
|
||||||
|
run: pip install pre-commit
|
||||||
|
|
||||||
|
- name: Run pre-commit hooks
|
||||||
|
run: pre-commit run --all-files --color always
|
||||||
|
|
||||||
|
- name: Install Poetry
|
||||||
|
run: |
|
||||||
|
pip install poetry
|
||||||
|
poetry self add poetry-plugin-export
|
||||||
|
|
||||||
|
- name: Install pip-audit
|
||||||
|
run: pip install pip-audit
|
||||||
|
|
||||||
|
- name: Audit dependencies (Poetry lockfile)
|
||||||
|
run: |
|
||||||
|
poetry export -f requirements.txt --without-hashes \
|
||||||
|
| pip-audit -r /dev/stdin
|
||||||
2
.gitignore
vendored
2
.gitignore
vendored
@@ -85,7 +85,7 @@ ipython_config.py
|
|||||||
# pyenv
|
# pyenv
|
||||||
# For a library or package, you might want to ignore these files since the code is
|
# For a library or package, you might want to ignore these files since the code is
|
||||||
# intended to run in multiple environments; otherwise, check them in:
|
# intended to run in multiple environments; otherwise, check them in:
|
||||||
# .python-version
|
.python-version
|
||||||
|
|
||||||
# pipenv
|
# pipenv
|
||||||
# According to pypa/pipenv#598, it is recommended to include Pipfile.lock in version control.
|
# According to pypa/pipenv#598, it is recommended to include Pipfile.lock in version control.
|
||||||
|
|||||||
51
README.md
51
README.md
@@ -4,6 +4,11 @@
|
|||||||
|
|
||||||
# chguard
|
# chguard
|
||||||
|
|
||||||
|
<div align="center">
|
||||||
|
<img src="https://git.sysmd.uk/guardutils/chguard/raw/branch/main/chguard.png" alt="chguard logo" width="256" />
|
||||||
|
</div>
|
||||||
|
|
||||||
|
|
||||||
**chguard** is a safety-first command-line tool that snapshots and restores
|
**chguard** is a safety-first command-line tool that snapshots and restores
|
||||||
filesystem ownership and permissions.
|
filesystem ownership and permissions.
|
||||||
|
|
||||||
@@ -25,6 +30,31 @@ A single confirmation prompt at the end of a restore (default: **No**).
|
|||||||
### Dry-run mode
|
### Dry-run mode
|
||||||
Preview restore operations without prompting or applying changes.
|
Preview restore operations without prompting or applying changes.
|
||||||
|
|
||||||
|
### Wrapper mode (automatic snapshots)
|
||||||
|
|
||||||
|
`chguard` can also run as a wrapper around ownership and permission commands.
|
||||||
|
In this mode, `chguard` automatically saves a snapshot before the command runs, so the user can easily restore the previous state if needed.
|
||||||
|
|
||||||
|
#### Supported commands
|
||||||
|
|
||||||
|
Wrapper mode is intentionally limited to commands that modify filesystem metadata only:
|
||||||
|
|
||||||
|
* `chown`
|
||||||
|
* `chmod`
|
||||||
|
* `chgrp`
|
||||||
|
|
||||||
|
Other commands are rejected to avoid giving a _false sense of protection_.
|
||||||
|
|
||||||
|
#### Automatic snapshot names
|
||||||
|
|
||||||
|
Snapshots created in wrapper mode are named automatically, for example:
|
||||||
|
|
||||||
|
```
|
||||||
|
auto-20251230-161301
|
||||||
|
```
|
||||||
|
|
||||||
|
Auto-generated snapshots are visually distinguished in the output so they are easy to identify.
|
||||||
|
|
||||||
### Scope control
|
### Scope control
|
||||||
Restore:
|
Restore:
|
||||||
* both ownership and permissions (default)
|
* both ownership and permissions (default)
|
||||||
@@ -50,7 +80,6 @@ Restore:
|
|||||||
|
|
||||||
It only concerns itself with **ownership** and **permissions**.
|
It only concerns itself with **ownership** and **permissions**.
|
||||||
|
|
||||||
|
|
||||||
## Installation
|
## Installation
|
||||||
|
|
||||||
### From GuardUtils package repo
|
### From GuardUtils package repo
|
||||||
@@ -174,6 +203,16 @@ chguard --restore app-baseline --permissions
|
|||||||
chguard --restore app-baseline --owner
|
chguard --restore app-baseline --owner
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Wrapper mode
|
||||||
|
|
||||||
|
Use `--` to separate `chguard` arguments from the wrapped command:
|
||||||
|
|
||||||
|
```
|
||||||
|
chguard -- chown user:group file
|
||||||
|
chguard -- chmod 755 file
|
||||||
|
chguard -- chgrp staff file
|
||||||
|
```
|
||||||
|
|
||||||
## Privilege model
|
## Privilege model
|
||||||
|
|
||||||
`chguard` never escalates privileges automatically
|
`chguard` never escalates privileges automatically
|
||||||
@@ -193,6 +232,16 @@ Snapshots are stored in a local SQLite database containing:
|
|||||||
|
|
||||||
Usernames and permission strings are resolved only for display.
|
Usernames and permission strings are resolved only for display.
|
||||||
|
|
||||||
|
### TAB completion
|
||||||
|
Add this to your `.bashrc`
|
||||||
|
```
|
||||||
|
eval "$(register-python-argcomplete chguard)"
|
||||||
|
```
|
||||||
|
And then
|
||||||
|
```
|
||||||
|
source ~/.bashrc
|
||||||
|
```
|
||||||
|
|
||||||
## pre-commit
|
## pre-commit
|
||||||
This project uses [**pre-commit**](https://pre-commit.com/) to run automatic formatting and security checks before each commit (Black, Bandit, and various safety checks).
|
This project uses [**pre-commit**](https://pre-commit.com/) to run automatic formatting and security checks before each commit (Black, Bandit, and various safety checks).
|
||||||
|
|
||||||
|
|||||||
BIN
chguard.png
Normal file
BIN
chguard.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 30 KiB |
309
chguard/cli.py
309
chguard/cli.py
@@ -1,11 +1,14 @@
|
|||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
import argparse
|
import argparse
|
||||||
|
import argcomplete
|
||||||
|
import importlib.metadata
|
||||||
import os
|
import os
|
||||||
import sys
|
import sys
|
||||||
import stat
|
import stat
|
||||||
import pwd
|
import pwd
|
||||||
import grp
|
import grp
|
||||||
|
import subprocess
|
||||||
from collections import Counter, defaultdict
|
from collections import Counter, defaultdict
|
||||||
from pathlib import Path
|
from pathlib import Path
|
||||||
from datetime import datetime
|
from datetime import datetime
|
||||||
@@ -27,8 +30,14 @@ from chguard.restore import plan_restore, apply_restore
|
|||||||
from chguard.util import normalize_root
|
from chguard.util import normalize_root
|
||||||
|
|
||||||
|
|
||||||
|
def get_version():
|
||||||
|
try:
|
||||||
|
return importlib.metadata.version("chguard")
|
||||||
|
except importlib.metadata.PackageNotFoundError:
|
||||||
|
return "unknown"
|
||||||
|
|
||||||
|
|
||||||
def _uid_to_name(uid: int) -> str:
|
def _uid_to_name(uid: int) -> str:
|
||||||
"""Return username for uid, or uid as string if unknown."""
|
|
||||||
try:
|
try:
|
||||||
return pwd.getpwuid(uid).pw_name
|
return pwd.getpwuid(uid).pw_name
|
||||||
except KeyError:
|
except KeyError:
|
||||||
@@ -36,7 +45,6 @@ def _uid_to_name(uid: int) -> str:
|
|||||||
|
|
||||||
|
|
||||||
def _gid_to_name(gid: int) -> str:
|
def _gid_to_name(gid: int) -> str:
|
||||||
"""Return group name for gid, or gid as string if unknown."""
|
|
||||||
try:
|
try:
|
||||||
return grp.getgrgid(gid).gr_name
|
return grp.getgrgid(gid).gr_name
|
||||||
except KeyError:
|
except KeyError:
|
||||||
@@ -44,12 +52,10 @@ def _gid_to_name(gid: int) -> str:
|
|||||||
|
|
||||||
|
|
||||||
def _format_owner(uid: int, gid: int) -> str:
|
def _format_owner(uid: int, gid: int) -> str:
|
||||||
"""Format uid/gid as username:group."""
|
|
||||||
return f"{_uid_to_name(uid)}:{_gid_to_name(gid)}"
|
return f"{_uid_to_name(uid)}:{_gid_to_name(gid)}"
|
||||||
|
|
||||||
|
|
||||||
def _mode_to_rwx(mode: int) -> str:
|
def _mode_to_rwx(mode: int) -> str:
|
||||||
"""Convert numeric mode to rwx-style permissions."""
|
|
||||||
bits = (
|
bits = (
|
||||||
stat.S_IRUSR,
|
stat.S_IRUSR,
|
||||||
stat.S_IWUSR,
|
stat.S_IWUSR,
|
||||||
@@ -79,10 +85,33 @@ def _mode_to_rwx(mode: int) -> str:
|
|||||||
|
|
||||||
|
|
||||||
def _is_root() -> bool:
|
def _is_root() -> bool:
|
||||||
"""Return True if running as root."""
|
|
||||||
return os.geteuid() == 0
|
return os.geteuid() == 0
|
||||||
|
|
||||||
|
|
||||||
|
def complete_state_names(prefix, parsed_args, **kwargs):
|
||||||
|
try:
|
||||||
|
conn = connect(
|
||||||
|
Path(parsed_args.db).expanduser().resolve()
|
||||||
|
if parsed_args.db
|
||||||
|
else None
|
||||||
|
)
|
||||||
|
rows = conn.execute("SELECT name FROM states").fetchall()
|
||||||
|
return [name for (name,) in rows if name.startswith(prefix)]
|
||||||
|
except Exception:
|
||||||
|
return []
|
||||||
|
|
||||||
|
|
||||||
|
def _extract_paths_from_command(cmd: list[str]) -> list[Path]:
|
||||||
|
paths = []
|
||||||
|
for arg in cmd:
|
||||||
|
if arg.startswith("-"):
|
||||||
|
continue
|
||||||
|
p = Path(arg)
|
||||||
|
if p.exists():
|
||||||
|
paths.append(p.resolve())
|
||||||
|
return paths
|
||||||
|
|
||||||
|
|
||||||
def main() -> None:
|
def main() -> None:
|
||||||
"""
|
"""
|
||||||
Entry point for the CLI.
|
Entry point for the CLI.
|
||||||
@@ -94,57 +123,205 @@ def main() -> None:
|
|||||||
- Symlinks are skipped during scanning
|
- Symlinks are skipped during scanning
|
||||||
"""
|
"""
|
||||||
|
|
||||||
|
wrapper_cmd = None
|
||||||
|
if "--" in sys.argv:
|
||||||
|
idx = sys.argv.index("--")
|
||||||
|
wrapper_cmd = sys.argv[idx + 1 :]
|
||||||
|
sys.argv = sys.argv[:idx]
|
||||||
|
|
||||||
parser = argparse.ArgumentParser(
|
parser = argparse.ArgumentParser(
|
||||||
prog="chguard",
|
prog="chguard",
|
||||||
description="Snapshot and restore filesystem ownership and permissions.",
|
description="Snapshot and restore filesystem ownership and permissions.",
|
||||||
)
|
)
|
||||||
|
|
||||||
actions = parser.add_mutually_exclusive_group(required=True)
|
parser = argparse.ArgumentParser(
|
||||||
actions.add_argument("--save", metavar="PATH", help="Save state for PATH")
|
prog="chguard",
|
||||||
|
description="Snapshot and restore filesystem ownership and permissions.",
|
||||||
|
epilog=(
|
||||||
|
"Wrapper mode:\n"
|
||||||
|
" chguard -- chown [OPTIONS] PATH...\n"
|
||||||
|
" chguard -- chmod [OPTIONS] PATH...\n"
|
||||||
|
" chguard -- chgrp [OPTIONS] PATH...\n\n"
|
||||||
|
"In wrapper mode, chguard automatically saves a snapshot of ownership\n"
|
||||||
|
"and permissions for the affected paths before running the command.\n"
|
||||||
|
"Only chown, chmod, and chgrp are supported."
|
||||||
|
),
|
||||||
|
formatter_class=argparse.RawDescriptionHelpFormatter,
|
||||||
|
)
|
||||||
|
|
||||||
|
actions = parser.add_mutually_exclusive_group(required=wrapper_cmd is None)
|
||||||
|
|
||||||
|
parser.add_argument(
|
||||||
|
"--version",
|
||||||
|
action="version",
|
||||||
|
version=f"chguard {get_version()}",
|
||||||
|
)
|
||||||
|
|
||||||
actions.add_argument(
|
actions.add_argument(
|
||||||
"--restore", action="store_true", help="Restore a saved state"
|
"--save",
|
||||||
)
|
metavar="PATH",
|
||||||
|
help="Save state for PATH",
|
||||||
|
).completer = argcomplete.FilesCompleter()
|
||||||
|
|
||||||
actions.add_argument(
|
actions.add_argument(
|
||||||
"--list", action="store_true", help="List saved states"
|
"--restore",
|
||||||
|
action="store_true",
|
||||||
|
help="Restore a saved state",
|
||||||
)
|
)
|
||||||
|
|
||||||
actions.add_argument(
|
actions.add_argument(
|
||||||
"--delete", metavar="STATE", help="Delete a saved state"
|
"--list",
|
||||||
|
action="store_true",
|
||||||
|
help="List saved states",
|
||||||
|
)
|
||||||
|
|
||||||
|
actions.add_argument(
|
||||||
|
"--delete",
|
||||||
|
metavar="STATE",
|
||||||
|
help="Delete a saved state",
|
||||||
|
).completer = complete_state_names
|
||||||
|
|
||||||
|
# positional STATE
|
||||||
|
parser.add_argument(
|
||||||
|
"state",
|
||||||
|
nargs="?",
|
||||||
|
help="State name (required with --restore)",
|
||||||
|
).completer = complete_state_names
|
||||||
|
|
||||||
|
parser.add_argument(
|
||||||
|
"--name",
|
||||||
|
help="State name (required with --save)",
|
||||||
)
|
)
|
||||||
|
|
||||||
parser.add_argument(
|
parser.add_argument(
|
||||||
"state", nargs="?", help="State name (required with --restore)"
|
"--overwrite",
|
||||||
)
|
action="store_true",
|
||||||
parser.add_argument("--name", help="State name (required with --save)")
|
help="Overwrite existing state",
|
||||||
parser.add_argument(
|
|
||||||
"--overwrite", action="store_true", help="Overwrite existing state"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
parser.add_argument(
|
parser.add_argument(
|
||||||
"--permissions", action="store_true", help="Restore MODE only"
|
"--permissions",
|
||||||
)
|
action="store_true",
|
||||||
parser.add_argument(
|
help="Restore MODE only",
|
||||||
"--owner", action="store_true", help="Restore OWNER only"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
parser.add_argument(
|
parser.add_argument(
|
||||||
"--dry-run", action="store_true", help="Preview only; do not apply"
|
"--owner",
|
||||||
)
|
action="store_true",
|
||||||
parser.add_argument(
|
help="Restore OWNER only",
|
||||||
"--yes", action="store_true", help="Apply without confirmation"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
parser.add_argument("--root", metavar="PATH", help="Override restore root")
|
|
||||||
parser.add_argument(
|
parser.add_argument(
|
||||||
"--exclude", action="append", default=[], help="Exclude path prefix"
|
"--dry-run",
|
||||||
|
action="store_true",
|
||||||
|
help="Preview only; do not apply",
|
||||||
)
|
)
|
||||||
parser.add_argument("--db", metavar="PATH", help="Override database path")
|
|
||||||
|
|
||||||
|
parser.add_argument(
|
||||||
|
"--yes",
|
||||||
|
action="store_true",
|
||||||
|
help="Apply without confirmation",
|
||||||
|
)
|
||||||
|
|
||||||
|
parser.add_argument(
|
||||||
|
"--root",
|
||||||
|
metavar="PATH",
|
||||||
|
help="Override restore root",
|
||||||
|
).completer = argcomplete.FilesCompleter()
|
||||||
|
|
||||||
|
parser.add_argument(
|
||||||
|
"--exclude",
|
||||||
|
action="append",
|
||||||
|
default=[],
|
||||||
|
help="Exclude path prefix",
|
||||||
|
).completer = argcomplete.FilesCompleter()
|
||||||
|
|
||||||
|
parser.add_argument(
|
||||||
|
"--db",
|
||||||
|
metavar="PATH",
|
||||||
|
help="Override database path",
|
||||||
|
).completer = argcomplete.FilesCompleter()
|
||||||
|
|
||||||
|
argcomplete.autocomplete(parser)
|
||||||
args = parser.parse_args()
|
args = parser.parse_args()
|
||||||
|
|
||||||
|
if wrapper_cmd is not None:
|
||||||
|
if not wrapper_cmd:
|
||||||
|
raise SystemExit("No command provided after '--'")
|
||||||
|
|
||||||
|
cmd = Path(wrapper_cmd[0]).name
|
||||||
|
|
||||||
|
if cmd not in ("chown", "chmod", "chgrp"):
|
||||||
|
raise SystemExit(
|
||||||
|
"Wrapper mode only supports chown, chmod, and chgrp"
|
||||||
|
)
|
||||||
|
|
||||||
console = Console()
|
console = Console()
|
||||||
|
|
||||||
conn = connect(Path(args.db).expanduser().resolve() if args.db else None)
|
conn = connect(Path(args.db).expanduser().resolve() if args.db else None)
|
||||||
init_db(conn)
|
init_db(conn)
|
||||||
|
|
||||||
|
if wrapper_cmd:
|
||||||
|
paths = _extract_paths_from_command(wrapper_cmd)
|
||||||
|
if paths:
|
||||||
|
auto_name = f"auto-{datetime.now().strftime('%Y%m%d-%H%M%S')}"
|
||||||
|
with conn:
|
||||||
|
root_path = str(Path(paths[0]).resolve())
|
||||||
|
state_id = create_state(
|
||||||
|
conn, auto_name, root_path, os.getuid(), commit=False
|
||||||
|
)
|
||||||
|
|
||||||
|
for path in paths:
|
||||||
|
if path.is_dir():
|
||||||
|
for entry in scan_tree(path):
|
||||||
|
if entry.uid == 0 and not _is_root():
|
||||||
|
raise SystemExit(
|
||||||
|
"This command affects root-owned files.\n"
|
||||||
|
"Please re-run with sudo."
|
||||||
|
)
|
||||||
|
conn.execute(
|
||||||
|
"""
|
||||||
|
INSERT INTO entries (state_id, path, type, mode, uid, gid)
|
||||||
|
VALUES (?, ?, ?, ?, ?, ?)
|
||||||
|
""",
|
||||||
|
(
|
||||||
|
state_id,
|
||||||
|
entry.path,
|
||||||
|
entry.type,
|
||||||
|
entry.mode,
|
||||||
|
entry.uid,
|
||||||
|
entry.gid,
|
||||||
|
),
|
||||||
|
)
|
||||||
|
else:
|
||||||
|
st = path.lstat()
|
||||||
|
if st.st_uid == 0 and not _is_root():
|
||||||
|
raise SystemExit(
|
||||||
|
"This command affects root-owned files.\n"
|
||||||
|
"Please re-run with sudo."
|
||||||
|
)
|
||||||
|
conn.execute(
|
||||||
|
"""
|
||||||
|
INSERT INTO entries (state_id, path, type, mode, uid, gid)
|
||||||
|
VALUES (?, ?, ?, ?, ?, ?)
|
||||||
|
""",
|
||||||
|
(
|
||||||
|
state_id,
|
||||||
|
str(path),
|
||||||
|
"file",
|
||||||
|
stat.S_IMODE(st.st_mode),
|
||||||
|
st.st_uid,
|
||||||
|
st.st_gid,
|
||||||
|
),
|
||||||
|
)
|
||||||
|
|
||||||
|
console.print(
|
||||||
|
f"Saved pre-command snapshot: [cyan]{auto_name}[/cyan]"
|
||||||
|
)
|
||||||
|
|
||||||
|
proc = subprocess.run(wrapper_cmd)
|
||||||
|
sys.exit(proc.returncode)
|
||||||
|
|
||||||
if args.list:
|
if args.list:
|
||||||
rows = conn.execute(
|
rows = conn.execute(
|
||||||
"SELECT name, root_path, created_at FROM states ORDER BY created_at DESC"
|
"SELECT name, root_path, created_at FROM states ORDER BY created_at DESC"
|
||||||
@@ -157,7 +334,10 @@ def main() -> None:
|
|||||||
for name, root, created in rows:
|
for name, root, created in rows:
|
||||||
dt = datetime.fromisoformat(created)
|
dt = datetime.fromisoformat(created)
|
||||||
ts = dt.strftime("%Y-%m-%d %H:%M:%S %z")
|
ts = dt.strftime("%Y-%m-%d %H:%M:%S %z")
|
||||||
console.print(f"{name}\t{root}\t[dim]{ts}[/dim]")
|
if name.startswith("auto-"):
|
||||||
|
console.print(f"[cyan]{name}[/cyan]\t{root}\t{ts}")
|
||||||
|
else:
|
||||||
|
console.print(f"{name}\t{root}\t{ts}")
|
||||||
return
|
return
|
||||||
|
|
||||||
if args.delete:
|
if args.delete:
|
||||||
@@ -172,42 +352,49 @@ def main() -> None:
|
|||||||
|
|
||||||
root = normalize_root(args.save)
|
root = normalize_root(args.save)
|
||||||
|
|
||||||
if state_exists(conn, args.name):
|
try:
|
||||||
if not args.overwrite:
|
with conn: # start transaction
|
||||||
raise SystemExit(
|
if state_exists(conn, args.name):
|
||||||
f"State '{args.name}' already exists (use --overwrite)"
|
if not args.overwrite:
|
||||||
)
|
raise SystemExit(
|
||||||
delete_state(conn, args.name)
|
f"State '{args.name}' already exists (use --overwrite)"
|
||||||
|
)
|
||||||
|
# if the new save fails, this delete_state step will also roll back
|
||||||
|
delete_state(conn, args.name, commit=False)
|
||||||
|
|
||||||
state_id = create_state(conn, args.name, str(root), os.getuid())
|
state_id = create_state(
|
||||||
|
conn, args.name, str(root), os.getuid(), commit=False
|
||||||
# Abort early if root-owned files exist and user is not root.
|
|
||||||
# This prevents creating snapshots that cannot be meaningfully restored.
|
|
||||||
for entry in scan_tree(root, excludes=args.exclude):
|
|
||||||
if entry.uid == 0 and not _is_root():
|
|
||||||
raise SystemExit(
|
|
||||||
"This path contains root-owned files.\n"
|
|
||||||
"Saving this state requires sudo."
|
|
||||||
)
|
)
|
||||||
|
|
||||||
conn.execute(
|
# Abort early if root-owned files exist and user is not root.
|
||||||
"""
|
# This prevents creating snapshots that cannot be meaningfully restored.
|
||||||
INSERT INTO entries (state_id, path, type, mode, uid, gid)
|
for entry in scan_tree(root, excludes=args.exclude):
|
||||||
VALUES (?, ?, ?, ?, ?, ?)
|
if entry.uid == 0 and not _is_root():
|
||||||
""",
|
raise SystemExit(
|
||||||
(
|
"This path contains root-owned files.\n"
|
||||||
state_id,
|
"Saving this state requires sudo."
|
||||||
entry.path,
|
)
|
||||||
entry.type,
|
|
||||||
entry.mode,
|
|
||||||
entry.uid,
|
|
||||||
entry.gid,
|
|
||||||
),
|
|
||||||
)
|
|
||||||
|
|
||||||
conn.commit()
|
conn.execute(
|
||||||
console.print(f"Saved state '{args.name}' for {root}")
|
"""
|
||||||
return
|
INSERT INTO entries (state_id, path, type, mode, uid, gid)
|
||||||
|
VALUES (?, ?, ?, ?, ?, ?)
|
||||||
|
""",
|
||||||
|
(
|
||||||
|
state_id,
|
||||||
|
entry.path,
|
||||||
|
entry.type,
|
||||||
|
entry.mode,
|
||||||
|
entry.uid,
|
||||||
|
entry.gid,
|
||||||
|
),
|
||||||
|
)
|
||||||
|
|
||||||
|
console.print(f"Saved state '{args.name}' for {root}")
|
||||||
|
return
|
||||||
|
|
||||||
|
except SystemExit:
|
||||||
|
raise
|
||||||
|
|
||||||
if args.restore:
|
if args.restore:
|
||||||
if not args.state:
|
if not args.state:
|
||||||
@@ -263,7 +450,7 @@ def main() -> None:
|
|||||||
] = f"{_format_owner(bu, bg)} → {_format_owner(au, ag)}"
|
] = f"{_format_owner(bu, bg)} → {_format_owner(au, ag)}"
|
||||||
counts["owner"] += 1
|
counts["owner"] += 1
|
||||||
|
|
||||||
if au != current_uid:
|
if ch.path.stat().st_uid != current_uid:
|
||||||
needs_root = True
|
needs_root = True
|
||||||
|
|
||||||
elif ch.kind == "mode" and restore_permissions:
|
elif ch.kind == "mode" and restore_permissions:
|
||||||
|
|||||||
@@ -61,19 +61,28 @@ def state_exists(conn: sqlite3.Connection, name: str) -> bool:
|
|||||||
|
|
||||||
|
|
||||||
def create_state(
|
def create_state(
|
||||||
conn: sqlite3.Connection, name: str, root_path: str, created_by_uid: int
|
conn: sqlite3.Connection,
|
||||||
|
name: str,
|
||||||
|
root_path: str,
|
||||||
|
created_by_uid: int,
|
||||||
|
*,
|
||||||
|
commit: bool = True,
|
||||||
) -> int:
|
) -> int:
|
||||||
cur = conn.execute(
|
cur = conn.execute(
|
||||||
"INSERT INTO states (name, root_path, created_at, created_by_uid) VALUES (?, ?, ?, ?)",
|
"INSERT INTO states (name, root_path, created_at, created_by_uid) VALUES (?, ?, ?, ?)",
|
||||||
(name, root_path, utc_now_iso(), created_by_uid),
|
(name, root_path, utc_now_iso(), created_by_uid),
|
||||||
)
|
)
|
||||||
conn.commit()
|
if commit:
|
||||||
|
conn.commit()
|
||||||
return int(cur.lastrowid)
|
return int(cur.lastrowid)
|
||||||
|
|
||||||
|
|
||||||
def delete_state(conn: sqlite3.Connection, name: str) -> int:
|
def delete_state(
|
||||||
|
conn: sqlite3.Connection, name: str, commit: bool = True
|
||||||
|
) -> int:
|
||||||
cur = conn.execute("DELETE FROM states WHERE name = ?", (name,))
|
cur = conn.execute("DELETE FROM states WHERE name = ?", (name,))
|
||||||
conn.commit()
|
if commit:
|
||||||
|
conn.commit()
|
||||||
return cur.rowcount
|
return cur.rowcount
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
2
poetry.lock
generated
2
poetry.lock
generated
@@ -289,4 +289,4 @@ test = ["covdefaults (>=2.3)", "coverage (>=7.2.7)", "coverage-enable-subprocess
|
|||||||
[metadata]
|
[metadata]
|
||||||
lock-version = "2.0"
|
lock-version = "2.0"
|
||||||
python-versions = ">=3.10,<4.0"
|
python-versions = ">=3.10,<4.0"
|
||||||
content-hash = "49f77d614e46109e49e997fa270cb7093d6f7e7d258e370c4eddd4354c20437f"
|
content-hash = "4a5c993fcc16fe3739c43eb00bed750ce0803d45e37c7a786aa0b83bb4930267"
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[tool.poetry]
|
[tool.poetry]
|
||||||
name = "chguard"
|
name = "chguard"
|
||||||
version = "0.1.0"
|
version = "0.3.0"
|
||||||
description = "Safety-first tool to snapshot and restore filesystem ownership and permissions."
|
description = "Safety-first tool to snapshot and restore filesystem ownership and permissions."
|
||||||
authors = ["Marco D'Aleo <marco@marcodaleo.com>"]
|
authors = ["Marco D'Aleo <marco@marcodaleo.com>"]
|
||||||
license = "GPL-3.0-or-later"
|
license = "GPL-3.0-or-later"
|
||||||
@@ -12,7 +12,8 @@ repository = "https://git.sysmd.uk/guardutils/chguard"
|
|||||||
python = ">=3.10,<4.0"
|
python = ">=3.10,<4.0"
|
||||||
rich = ">=12"
|
rich = ">=12"
|
||||||
argcomplete = ">=2"
|
argcomplete = ">=2"
|
||||||
platformdirs = "^4.5.1"
|
platformdirs = ">=4.5.1"
|
||||||
|
filelock = ">=3.20.1"
|
||||||
|
|
||||||
[tool.poetry.scripts]
|
[tool.poetry.scripts]
|
||||||
chguard = "chguard.cli:main"
|
chguard = "chguard.cli:main"
|
||||||
|
|||||||
Reference in New Issue
Block a user