[client] Profile ownership console user tofu (#7529)

* Add consoleuser and stamp default profile on known username in migration

* Refactor consoleuser to verify Id, fix seats on linux and default stamp

* Add default profile claim

* Add disable auto-claim of default profile and always fail close

* Add disable auto-claim flag to migration

* Adding timeout to console user on Linux and close library load on darwin

* Fixed failed close test

* Close both Dlopen for darwin

* Replace RegisterFunc with purego.Dlsym to avoid possible panic

* Fix freebsd tty enumeration

* Fix active profile migration logic and add test

* Log defaultClaimDisabled error once

* Guard against panicking console user lookup.

* Fix merge conflict

* Fix broken tests
This commit is contained in:
Theodor Midtlien
2026-09-17 11:20:13 +02:00
committed by GitHub
parent 52b16e7a5c
commit 90052cbefb
12 changed files with 712 additions and 13 deletions
+21 -3
View File
@@ -177,7 +177,8 @@ func undoMoves(moved []movedFile) {
}
// stampActiveUserDir records the owner of every unowned profile in the
// directory of the account the active profile state names.
// directory of the account the active profile state names and the default
// profile.
//
// That name is the one lossless input the old layout left behind. Resolving it
// forward, from name to uid, avoids reversing a sanitized directory name, which
@@ -198,21 +199,38 @@ func (s *ServiceManager) stampActiveUserDir(profiles []Profile, active *ActivePr
}
dir := sanitizeProfileName(active.Username)
if dir == "" {
log.Warnf("account %q leaves nothing after sanitizing, so its per-username profiles stay unowned", active.Username)
}
for i := range profiles {
p := &profiles[i]
if len(p.Owners) > 0 || p.LegacyUserDir != dir {
if len(p.Owners) > 0 || !takesActiveAccountOwner(p, dir) {
continue
}
if err := stampPrincipal(p.Path, principal); err != nil {
log.Warnf("leaving %s unowned, its owner could not be recorded: %v", p.Path, err)
continue
}
log.Infof("recorded %s as the owner of %s, the directory it sits in is that account's", principal, p.Path)
log.Infof("recorded %s as the owner of %s, the account the active profile state names", principal, p.Path)
}
return nil
}
// takesActiveAccountOwner reports whether an unowned profile should be stamped
// with the active account's principal, dir being the legacy directory name that
// account produced.
//
// An empty dir is the absence of a directory, not a directory whose name is
// empty, so nothing matches it.
func takesActiveAccountOwner(p *Profile, dir string) bool {
if dir != "" && p.LegacyUserDir == dir {
return true
}
return p.ID == defaultProfileName && !defaultProfileClaimDisabled()
}
// principalForUser turns a resolved account into an owner principal. os/user
// reports a numeric id on Unix and a SID on Windows, which is what tells the
// two kinds apart without a build tag.