Skip to content

Commit f28238c

Browse files
committed
fix: force config.json to 644 root:root to avoid permission denied on restart
1 parent b9adfa7 commit f28238c

1 file changed

Lines changed: 8 additions & 10 deletions

File tree

‎xray_deploy.sh‎

Lines changed: 8 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -350,13 +350,11 @@ validate_and_install_config() {
350350
echo -e "${YELLOW}⚠ xray 二进制尚未安装,跳过 -test 校验${NC}"
351351
fi
352352

353-
# 继承现有配置的 owner/group;xray.service 可能以 nobody 运行,root:root 600 会导致 permission denied
354-
local config_owner_group="root:root"
355-
if [ -f "$CONFIG_FILE" ]; then
356-
config_owner_group=$(stat -c "%U:%G" "$CONFIG_FILE" 2>/dev/null || echo "root:root")
357-
elif id nobody >/dev/null 2>&1; then
358-
config_owner_group="nobody:nogroup"
359-
fi
353+
# config.json 必须让 xray 服务用户(nobody)能读
354+
# 历史教训:盲目继承现有文件 owner/group 会延续错误(一旦老文件是 600 root:root,
355+
# 新文件继续 600,nobody 永远读不到,启动 permission denied)
356+
# 直接强制 644 root:root:/usr/local/etc/xray/ 目录默认 755 只有 root 能进入,
357+
# 即便文件 644 也不会泄露给非特权本地用户
360358

361359
# 备份原配置
362360
if [ -f "$CONFIG_FILE" ]; then
@@ -370,10 +368,10 @@ validate_and_install_config() {
370368
echo -e " ✓ 已备份原配置: $backup"
371369
fi
372370

373-
# 原子替换
371+
# 原子替换 + 强制权限到 nobody 可读
374372
mv "$new_config" "$CONFIG_FILE"
375-
chown "$config_owner_group" "$CONFIG_FILE" 2>/dev/null || true
376-
chmod 600 "$CONFIG_FILE"
373+
chown root:root "$CONFIG_FILE" 2>/dev/null || true
374+
chmod 644 "$CONFIG_FILE"
377375
return 0
378376
}
379377

0 commit comments

Comments
 (0)