Ensure MacOS desktop app launched as correct user (#27296)
For #25924 This PR attempts to fix the issue where the Fleet desktop icon sometimes fails to appear on MacOS hosts until the hosts are rebooted. Anecdotal evidence points to this being an issue when system setup is happening, leading to the theory that Orbit is attempting to launch the app as `_mbsetupuser` rather than the real logged-in user. The fix here is to use a different command to get the name of the logged-in user (ignoring `_mbsetupuser` if it appears), and to launch the desktop app as that user using `sudo`. I have tested this on MacOS and Ubuntu hosts, and verified that the desktop app launches as expected on both. We don't have a solid reproduction scenario for the issue, but we do have [some ways to look for relevant errors](https://github.com/fleetdm/fleet/issues/19172#issuecomment-2627812786), so we can try this out and see if those errors cease.
This commit is contained in:
@@ -12,6 +12,7 @@ type eopts struct {
|
||||
args [][2]string
|
||||
stderrPath string //nolint:structcheck,unused
|
||||
timeout time.Duration
|
||||
user string
|
||||
}
|
||||
|
||||
// Option allows configuring the application.
|
||||
@@ -38,6 +39,13 @@ func WithTimeout(duration time.Duration) Option {
|
||||
}
|
||||
}
|
||||
|
||||
// WithUser sets the user to run the application as. Currently only supported on MacOS.
|
||||
func WithUser(user string) Option {
|
||||
return func(a *eopts) {
|
||||
a.user = user
|
||||
}
|
||||
}
|
||||
|
||||
// Run runs an application as the current login user.
|
||||
// It assumes the caller is running with high privileges (root on Unix, SYSTEM on Windows).
|
||||
//
|
||||
|
||||
@@ -41,7 +41,8 @@ func run(path string, opts eopts) (lastLogs string, err error) {
|
||||
}
|
||||
}
|
||||
|
||||
cmd := exec.Command("/usr/bin/open", arg...)
|
||||
arg = append([]string{"-u", opts.user, "/usr/bin/open"}, arg...)
|
||||
cmd := exec.Command("sudo", arg...)
|
||||
tw := &TransientWriter{}
|
||||
cmd.Stderr = io.MultiWriter(tw, os.Stderr)
|
||||
cmd.Stdout = io.MultiWriter(tw, os.Stdout)
|
||||
|
||||
Reference in New Issue
Block a user