Client-mode log directory is created under the umask, unlike the daemon's state directory
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
調査の方向性
Start with daemon::state_perms::ensure_owner_only_dir, then inspect engine::resolve_log_dir and the directory-creation call sites in hyperdb-mcp/src/main.rs and hyperdb-mcp/src/engine.rs. Check how Engine::new passes log_dir to hyperd and consider the adjacent ephemeral data directory. Done means client-mode log directories follow the daemon's owner-only policy, with the related data directory considered consistently.
索引モデルが issue の本文から書いたものです。
説明
Summary
The daemon's state directory and logs/ are created with an explicit owner-only mode
(daemon::state_perms, added in #295). The client/local-mode log directory is not: both
call sites use a plain std::fs::create_dir_all, so it takes the process umask — commonly
0755.
That directory holds the same class of file. In local mode Engine::new passes it to hyperd
as the engine's own log_dir, so hyperd writes its diagnostic logs there, and those records
name the endpoint just as the daemon's logs/ do. Restricting the daemon's state directory
while leaving the client's log directory at the umask is an inconsistency rather than a
deliberate difference.
Where
engine::resolve_log_dir(hyperdb-mcp/src/engine.rs) returns either the persistent file's
parent, orstd::env::temp_dir().join(format!("hyperdb-mcp-{pid}"))when the session is
ephemeral.- Both call sites create it with a plain
create_dir_all:hyperdb-mcp/src/main.rs(client-modetracingsetup, writeshyperdb-mcp.log)hyperdb-mcp/src/engine.rs(Engine::new)
Engine::newthen setsparams.set("log_dir", …)for the localHyperProcess, sohyperd
rotates its own logs into the same directory.- The adjacent ephemeral data directory (
hyperdb-mcp-<pid>-<seq>, holding the session's
.hyperfiles) is created the same way and is worth considering in the same pass.
Why it varies by platform
The ephemeral case is the one that matters, and how much depends on the platform:
- Linux —
temp_dir()is/tmp, which is shared and world-traversable, and the directory
name is just the pid. This is the case worth fixing. - macOS —
temp_dir()is a per-user/var/folders/…directory that is already0700, so
the parent covers it. - Windows — the per-user temp directory sits inside the user profile and inherits its ACL.
Suggested fix
Reuse daemon::state_perms::ensure_owner_only_dir at both call sites instead of
create_dir_all. It already creates at 0700, tightens a pre-existing directory, sweeps the
regular files inside it, and warns rather than failing when the filesystem has no modes to set
— the same policy the daemon paths use, which is what makes this a consistency fix rather than
a new one. Consider the ephemeral data directory too.
Notes
- Ordinary file-permission hygiene, not an urgent defect: on macOS and Windows the enclosing
directory already restricts access, and on Linux it affects a local developer tool's own
diagnostic output. - Deliberately out of scope for #295, which is about the daemon's state directory.
- Whether the client's own
hyperdb-mcp.logrecords the endpoint was not established —
notracingcall inengine.rs,server.rsormain.rsemits it as a field, though the
endpoint does appear in the text of a connect-failure message. Thehyperdlogs in the same
directory are the clear case, and they are enough to motivate the change.
- 主要言語
- Rust
- スター
- 3
- フォーク
- 2
- 平均マージ
- 23時間 11分
- マージ済み PR(30日)
- 65
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
tableau/hyper-api-rust のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
tableau/hyper-api-rust#294 ·
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
tableau/hyper-api-rust#311 ·
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 45/100
tableau/hyper-api-rust#305 ·
メンテナーはふだん 1 日以内に返信
-
Windows Named Pipe: verify DACL denies other users, and measure read-path perf for MCP workloadsオープン
難易度 4/5 3〜5日 初心者へのやさしさ 38/100
tableau/hyper-api-rust#302 ·
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 72/100
tableau/hyper-api-rust#300 ·
メンテナーはふだん 1 日以内に返信
tableau/hyper-api-rust の issue をすべて見る
似ている issue
-
good first issue help wanted
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
-
documentation
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
NuSkooler/enigma-bbs#907 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
メンテナーはふだん 1 日以内に返信
-
bug pixi-build-r
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
prefix-dev/pixi#7229 ·
メンテナーはふだん 1 日以内に返信