Ensure MacOS desktop app launched as correct user (#27296)

For #25924  

This PR attempts to fix the issue where the Fleet desktop icon sometimes
fails to appear on MacOS hosts until the hosts are rebooted. Anecdotal
evidence points to this being an issue when system setup is happening,
leading to the theory that Orbit is attempting to launch the app as
`_mbsetupuser` rather than the real logged-in user. The fix here is to
use a different command to get the name of the logged-in user (ignoring
`_mbsetupuser` if it appears), and to launch the desktop app as that
user using `sudo`.

I have tested this on MacOS and Ubuntu hosts, and verified that the
desktop app launches as expected on both.

We don't have a solid reproduction scenario for the issue, but we do
have [some ways to look for relevant
errors](https://github.com/fleetdm/fleet/issues/19172#issuecomment-2627812786),
so we can try this out and see if those errors cease.
This commit is contained in:
Scott Gress
2025-03-20 09:49:23 -05:00
committed by GitHub
parent 8ef3ff2ae5
commit 866d8bcc00
6 changed files with 45 additions and 23 deletions
+8
View File
@@ -12,6 +12,7 @@ type eopts struct {
args [][2]string
stderrPath string //nolint:structcheck,unused
timeout time.Duration
user string
}
// Option allows configuring the application.
@@ -38,6 +39,13 @@ func WithTimeout(duration time.Duration) Option {
}
}
// WithUser sets the user to run the application as. Currently only supported on MacOS.
func WithUser(user string) Option {
return func(a *eopts) {
a.user = user
}
}
// Run runs an application as the current login user.
// It assumes the caller is running with high privileges (root on Unix, SYSTEM on Windows).
//
+2 -1
View File
@@ -41,7 +41,8 @@ func run(path string, opts eopts) (lastLogs string, err error) {
}
}
cmd := exec.Command("/usr/bin/open", arg...)
arg = append([]string{"-u", opts.user, "/usr/bin/open"}, arg...)
cmd := exec.Command("sudo", arg...)
tw := &TransientWriter{}
cmd.Stderr = io.MultiWriter(tw, os.Stderr)
cmd.Stdout = io.MultiWriter(tw, os.Stdout)