aboutsummaryrefslogtreecommitdiffhomepage
diff options
context:
space:
mode:
-rw-r--r--cmd/mbf/cache.go8
-rw-r--r--cmd/mbf/main.go2
2 files changed, 9 insertions, 1 deletions
diff --git a/cmd/mbf/cache.go b/cmd/mbf/cache.go
index 0e20ca99..166e1c45 100644
--- a/cmd/mbf/cache.go
+++ b/cmd/mbf/cache.go
@@ -2,6 +2,7 @@ package main
import (
"context"
+ "errors"
"net/http"
"os"
"path/filepath"
@@ -14,6 +15,9 @@ import (
"hakurei.app/pkg"
)
+// poisonOpen is whether cache.open is poisoned. This enables running as root.
+var _, poisonOpen = os.LookupEnv("MBF_POISON_OPEN")
+
// cache refers to an instance of [pkg.Cache] that might be open.
type cache struct {
ctx context.Context
@@ -49,6 +53,10 @@ func writeTitle(msg message.Msg, s string) {
// open opens the underlying [pkg.Cache].
func (cache *cache) open() (err error) {
+ if poisonOpen {
+ return errors.New("attempting to open cache")
+ }
+
if cache.c != nil {
return os.ErrInvalid
}
diff --git a/cmd/mbf/main.go b/cmd/mbf/main.go
index 014a7f47..5dd4e8a0 100644
--- a/cmd/mbf/main.go
+++ b/cmd/mbf/main.go
@@ -71,7 +71,7 @@ func main() {
log.SetPrefix("mbf: ")
msg := message.New(log.Default())
- if os.Geteuid() == 0 {
+ if !poisonOpen && os.Geteuid() == 0 {
log.Fatal("this program must not run as root")
}