DC-050 harden dataDir + add image-layer migration
Three-part fix for the silent data-loss failure mode that survives DC-039:
If SERVICES_FILE env was unset, platformPaths.dataDir resolved to /etc/dashcaddy
(image-layer path), and audit/license/error logs would silently land there and
vanish on every container recreate.
1. platform-paths.assertSafe({mode:'production'}) — throws FATAL on forbidden
zones (/app/src,routes,scripts,utils,managers,security + /etc/* + /usr + /var).
Bypassed with SKIP_DATA_DIR_GUARD=1.
2. server.js calls assertSafe() before any runtime work.
3. start.sh one-time migration: scans 6 known image-layer zombie paths,
copies non-empty content to bind mount with 'migrated-' prefix,
gated by sentinel file. Survives set -e per-file failures.
19/19 platform-paths tests + 5/5 shell migration tests.
Suite: 1066/1067 (1 pre-existing public-routes-drift failure from in-flight
auth refactor, untouched by this commit).
Verified live on DNS2: live audit log at /app/data/audit-log.json (315KB,
active) is unaffected; vestigial 2-byte /app/src/security/audit-log.json +
140KB /app/src/utils/error.log (pre-DC-039 era) will be recovered on next
container recreate.
This commit is contained in:
@@ -112,6 +112,98 @@ describe('Platform Paths — cross-platform path resolution', () => {
|
||||
}
|
||||
});
|
||||
|
||||
// ============================================================================
|
||||
// dataDir safety guard — DC-046 follow-up to DC-039. Catches the silent
|
||||
// failure mode where SERVICES_FILE isn't set as an env var and resolution
|
||||
// falls back to a path inside the Docker image layer.
|
||||
// ============================================================================
|
||||
describe('assertSafe (DC-046 follow-up to DC-039)', () => {
|
||||
if (process.platform !== 'linux') {
|
||||
it('is a no-op on non-Linux platforms (Windows uses different path tree)', () => {
|
||||
const paths = loadPaths();
|
||||
expect(() => paths.assertSafe({ mode: 'production' })).not.toThrow();
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
it('throws when SERVICES_FILE unset and CADDY_BASE resolves to /etc/dashcaddy', () => {
|
||||
delete process.env.SERVICES_FILE;
|
||||
delete process.env.DATA_DIR;
|
||||
process.env.SKIP_DATA_DIR_GUARD = ''; // ensure guard active
|
||||
const paths = loadPaths();
|
||||
// Force /etc/dashcaddy via env vars to simulate the regression path
|
||||
process.env.CADDY_BASE = '/etc/dashcaddy';
|
||||
const loaded = loadPaths();
|
||||
expect(() => loaded.assertSafe({ mode: 'production' })).toThrow(/forbidden image-layer/);
|
||||
});
|
||||
|
||||
it('throws when dataDir resolves into /app/src', () => {
|
||||
process.env.SERVICES_FILE = '/app/src/security/foo.json';
|
||||
const paths = loadPaths();
|
||||
expect(() => paths.assertSafe({ mode: 'production' })).toThrow(/forbidden image-layer/);
|
||||
});
|
||||
|
||||
it('throws when dataDir resolves into /app/routes', () => {
|
||||
process.env.SERVICES_FILE = '/app/routes/auth/services.json';
|
||||
const paths = loadPaths();
|
||||
expect(() => paths.assertSafe({ mode: 'production' })).toThrow(/forbidden image-layer/);
|
||||
});
|
||||
|
||||
it('allows dataDir at /app/data (the standard production bind mount)', () => {
|
||||
process.env.SERVICES_FILE = '/app/data/services.json';
|
||||
const paths = loadPaths();
|
||||
expect(() => paths.assertSafe({ mode: 'production' })).not.toThrow();
|
||||
});
|
||||
|
||||
it('allows dataDir at /opt/some-bind-mount', () => {
|
||||
process.env.SERVICES_FILE = '/opt/dashcaddy/dashcaddy-api/data/services.json';
|
||||
const paths = loadPaths();
|
||||
expect(() => paths.assertSafe({ mode: 'production' })).not.toThrow();
|
||||
});
|
||||
|
||||
it('is a no-op when mode !== production (dev/test path)', () => {
|
||||
process.env.SERVICES_FILE = '/app/src/security/foo.json'; // would otherwise throw
|
||||
const paths = loadPaths();
|
||||
expect(() => paths.assertSafe({ mode: 'development' })).not.toThrow();
|
||||
expect(() => paths.assertSafe({ mode: 'test' })).not.toThrow();
|
||||
// Default mode is 'production' → a forbidden path MUST throw.
|
||||
expect(() => paths.assertSafe()).toThrow(/forbidden image-layer/);
|
||||
});
|
||||
|
||||
it('is bypassed when SKIP_DATA_DIR_GUARD is set (escape hatch for legacy setups)', () => {
|
||||
process.env.SERVICES_FILE = '/app/src/security/foo.json';
|
||||
process.env.SKIP_DATA_DIR_GUARD = '1';
|
||||
const paths = loadPaths();
|
||||
expect(paths.assertSafe).toBeDefined();
|
||||
// Loader short-circuits if SKIP_DATA_DIR_GUARD was active at module load;
|
||||
// verify via fresh require after re-setting it
|
||||
delete require.cache[require.resolve('../platform-paths')];
|
||||
const loaded = require('../platform-paths');
|
||||
expect(() => loaded.assertSafe({ mode: 'production' })).not.toThrow();
|
||||
});
|
||||
});
|
||||
|
||||
describe('isMountedCheck', () => {
|
||||
it('returns false for non-existent paths', () => {
|
||||
const paths = loadPaths();
|
||||
expect(paths.isMountedCheck('/this/does/not/exist/at/all/abc123')).toBe(false);
|
||||
});
|
||||
|
||||
it('returns true for /tmp (writable on every Linux system)', () => {
|
||||
const paths = loadPaths();
|
||||
expect(paths.isMountedCheck('/tmp')).toBe(true);
|
||||
});
|
||||
|
||||
it('returns false for /app alone (image layer without /app/data sub-mount)', () => {
|
||||
const paths = loadPaths();
|
||||
// In a Docker container this would be /app/data being a separate fs.
|
||||
// In a plain Linux test env, /app likely doesn't exist anyway.
|
||||
// Either way, the predicate should not throw and should return a boolean.
|
||||
const result = paths.isMountedCheck('/app');
|
||||
expect(typeof result).toBe('boolean');
|
||||
});
|
||||
});
|
||||
|
||||
describe('Windows-specific defaults', () => {
|
||||
if (process.platform === 'win32') {
|
||||
it('caddyBase defaults to C:/caddy', () => {
|
||||
|
||||
Reference in New Issue
Block a user