修复 daemon 启动问题,分离 GUI 和 daemon 二进制
- 分离二进制: cmd/lmvpn (GUI+Fyne) 和 cmd/lmvpnd (daemon, 无 Fyne)
消除 daemon 启动时的 Fyne locale 初始化错误
- 新增 daemon-launch 子命令: 用 syscall.SysProcAttr{Setsid: true}
替代 nohup, 解决 osascript 无 TTY 时的 'Inappropriate ioctl' 错误
- daemon 日志写到用户家目录: paths.SetUserHome() 覆盖 root 默认路径
- IPC socket chown 给用户: 解决 root:wheel 0660 导致 GUI 无法连接
- 修复 JWT→密码认证回退: 捕获 ServerError{auth_err} 而非仅 AuthError
- 修复 token URL 编码: 用 url.QueryEscape 替代裸拼接
- 日志去重: LMVPN_DAEMON=1 时 daemon 不再 stderr 镜像到文件
- Makefile 构建双二进制并打包到 .app bundle
This commit is contained in:
@@ -6,6 +6,11 @@
|
||||
// The daemon is launched (as root) by the GUI via osascript. It holds
|
||||
// no persistent state — all configuration is provided by the GUI in
|
||||
// the Start command.
|
||||
//
|
||||
// The daemon accepts --user-home, --uid, and --gid flags so it can:
|
||||
// - Write logs to the user's ~/Library/Logs/ (not /var/root)
|
||||
// - Chown the IPC socket so the user can connect
|
||||
// - Chown log files so the user can read them
|
||||
package daemon
|
||||
|
||||
import (
|
||||
@@ -26,9 +31,24 @@ import (
|
||||
|
||||
// Run starts the daemon and blocks until Shutdown is received or a
|
||||
// signal (SIGINT/SIGTERM) is delivered.
|
||||
func Run() error {
|
||||
//
|
||||
// userHome, uid, gid are the invoking GUI user's home directory and
|
||||
// IDs, used to place logs in the user's Library and chown the IPC
|
||||
// socket so the non-root GUI can connect.
|
||||
func Run(userHome string, uid, gid int) error {
|
||||
// Override paths to use the user's home directory (not root's).
|
||||
paths.SetUserHome(userHome)
|
||||
if err := paths.EnsureDirs(); err != nil {
|
||||
// Non-fatal: root can usually create these anyway.
|
||||
fmt.Fprintf(os.Stderr, "ensure dirs: %v\n", err)
|
||||
}
|
||||
|
||||
log.Init(log.RoleDaemon, paths.DaemonLogFile())
|
||||
log.L().Info("lmvpn daemon starting")
|
||||
// Chown the daemon log file so the user can read it.
|
||||
chownToUser(paths.DaemonLogFile(), uid, gid)
|
||||
|
||||
log.L().Info("lmvpn daemon starting",
|
||||
"user_home", userHome, "uid", uid, "gid", gid)
|
||||
|
||||
server, err := ipc.NewServer()
|
||||
if err != nil {
|
||||
@@ -36,6 +56,12 @@ func Run() error {
|
||||
}
|
||||
defer server.Close()
|
||||
|
||||
// Chown the IPC socket so the non-root GUI process can connect.
|
||||
// This is the critical fix: without it, the socket is owned by
|
||||
// root:wheel with mode 0660, and the user cannot dial it.
|
||||
chownToUser(paths.IPCSocketPath(), uid, gid)
|
||||
log.L().Info("daemon listening", "socket", paths.IPCSocketPath())
|
||||
|
||||
d := &daemon{server: server}
|
||||
|
||||
// Signal handling for clean shutdown.
|
||||
@@ -49,10 +75,20 @@ func Run() error {
|
||||
os.Exit(0)
|
||||
}()
|
||||
|
||||
log.L().Info("daemon listening", "socket", paths.IPCSocketPath())
|
||||
return server.Accept(d.handle)
|
||||
}
|
||||
|
||||
// chownToUser changes the ownership of a file to the given uid:gid.
|
||||
// Errors are logged but not fatal (e.g. if uid is -1).
|
||||
func chownToUser(path string, uid, gid int) {
|
||||
if uid < 0 {
|
||||
return
|
||||
}
|
||||
if err := os.Chown(path, uid, gid); err != nil {
|
||||
log.L().Warn("chown failed", "path", path, "error", err)
|
||||
}
|
||||
}
|
||||
|
||||
type daemon struct {
|
||||
server *ipc.Server
|
||||
session *vpn.SessionManager
|
||||
|
||||
Reference in New Issue
Block a user