Frun1na opened a new issue, #5669:
URL: https://github.com/apache/rocketmq-dashboard/issues/5669

   ### Before Creating the Bug Report
   
   - [x] I have searched the [open 
issues](https://github.com/apache/rocketmq-dashboard/issues) of this repository 
and believe that this is not a duplicate.
   - [x] This is a defect in RocketMQ Studio, not a usage question and not a 
defect in another Apache RocketMQ repository.
   - [x] I can reproduce this on the current `master` branch, or I have stated 
the exact version I am running below.
   
   ### Studio Version
   
   branch: `rocketmq-studio`
   git commit id: `6a68042f`
   deployed as: built from source (`go build .` in `rmqctl/`)
   
   ### Runtime Environment
   
   OS: Ubuntu 22.04 (WSL2)
   MySQL: not applicable — the defect is in the CLI's own config directory 
handling
   browser: not applicable
   
   ### Connected RocketMQ Cluster
   
   RocketMQ version: not applicable — the failure happens before any cluster 
call
   access mode: not applicable
   deployment: not applicable
   
   ### Describe the Bug
   
   `rmqctl` reads its config from a directory that must be exactly `0700` for 
writes but has no directory requirement for reads, so a config file the CLI 
happily loads can become unwritable depending only on the permissions of the 
directory that already contains it:
   
   - `Store.Save` calls `ensureConfigDirectory(filepath.Dir(path))` 
(`internal/config/permissions_unix.go`), which after `MkdirAll(path, 0700)` 
rejects anything whose mode is not exactly `0700`: `config directory <dir> must 
have permissions 0700 (found 0755)`.
   - `Load` validates only the file (`checkFilePermissions`: regular file, mode 
`& 0o077 == 0`), so the same path reads fine.
   
   Both the explicit `--config <dir>/config.yaml` form and the default 
`~/.rmqctl/config.yaml` are affected whenever the directory already exists with 
default permissions (`~/.config/rmqctl` created by hand, a shared checkout, or 
a `~/.rmqctl` created outside the CLI): every command that reads works, and 
every command that writes fails — `config set-context`, `use-context`, 
`delete-context` — with `COMMAND_FAILED` and a hint about command arguments 
that has nothing to do with the cause.
   
   The Java side takes the other approach for the same class of directory: 
`RmqctlWorkspace` creates its directories with `0700` and tightens an existing 
one (`Files.createDirectories(..., OWNER_ONLY_DIRECTORY)` followed by 
`chmod(directory, OWNER_ONLY_DIRECTORY)`), instead of refusing to use it.
   
   ```
   $ mkdir -m 755 ~/.config/rmqctl && install -m 600 config.yaml 
~/.config/rmqctl/config.yaml
   $ rmqctl --config ~/.config/rmqctl/config.yaml config get-contexts     # 
works
   $ rmqctl --config ~/.config/rmqctl/config.yaml config use-context local
   error [COMMAND_FAILED]: config directory /home/<user>/.config/rmqctl must 
have permissions 0700 (found 0755)
   hint: Review the command arguments and current context, or run the command 
with --help.
   $ chmod 700 ~/.config/rmqctl && rmqctl --config ~/.config/rmqctl/config.yaml 
config use-context local
   current context: local
   ```
   
   ### Steps to Reproduce
   
   1. Build the CLI: `cd rmqctl && go build .`.
   2. Create the config under a directory with the default permissions and a 
`0600` file, for example `mkdir -m 755 /tmp/rmqctl && install -m 600 
config.yaml /tmp/rmqctl/config.yaml`.
   3. `rmqctl --config /tmp/rmqctl/config.yaml config get-contexts` — reads 
fine, exit 0.
   4. `rmqctl --config /tmp/rmqctl/config.yaml config use-context <context>` — 
fails with the message above, exit 1.
   5. Repeat with the default path (`~/.rmqctl` created as `0755`): same 
asymmetry.
   6. `chmod 700` the directory and the failing command succeeds unchanged.
   
   ### What Did You Expect to See?
   
   One permission policy for the config location. Either an existing directory 
is accepted when it is not writable by group/other (the check the file itself 
already gets), or the CLI tightens it to `0700` the way the Java workspace 
does, or writing is refused only when the directory really is wider than the 
CLI can accept — with an error that says so and a hint that names the fix.
   
   ### What Did You See Instead?
   
   Reads that succeed and writes that fail on the same path, with an 
exact-match `0700` requirement that no documentation states, and a generic hint.
   
   ### Additional Context
   
   - `docs/ai-agent-architecture.md` documents only the file side ("`--config` 
required, yaml must be `0600`"), so the directory rule is an implementation 
detail that a user cannot discover without hitting it.
   - raising this as a report rather than a patch because the direction is a 
security/usability trade-off: accepting `0755` for a `0600` config file in it 
is normal on Unix, while requiring `0700` on the directory is stricter than the 
file check the same code applies to the file itself.
   
   ### Are You Willing to Submit a Pull Request?
   
   - [x] Yes, I am willing to submit a pull request.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to