Harden C2 file logging for Baota permission failures.

Swallow create_log mkdir/write errors so missing public/log ownership cannot take down requests, and document the www:www permission fix.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
hashbro
2026-08-09 16:07:56 +08:00
parent 6489808fa5
commit 6bf33e2761
3 changed files with 39 additions and 21 deletions
+25 -20
View File
@@ -6,32 +6,37 @@ if (! function_exists('create_log')) {
/**
* Append a line to public/log/{type}/Ymd.log
*
* Failures are swallowed so logging never breaks the HTTP request
* (e.g. www cannot mkdir under public/ on a fresh Baota deploy).
*
* @param array|string $str
*/
function create_log($str, string $type = 'c2'): void
{
$str = is_array($str) ? json_encode($str, JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES) : (string) $str;
$logPath = public_path('log/'.$type);
if (! is_dir($logPath)) {
$old = umask(0);
mkdir($logPath, 0777, true);
umask($old);
}
$logName = $logPath.'/'.date('Ymd').'.log';
try {
$url = request()->getRequestUri();
} catch (\Throwable) {
$url = $_SERVER['REQUEST_URI'] ?? '';
}
$logStr = date('Y-m-d H:i:s').' '.$url.' '.$str."\r\n\r\n";
$isNew = ! file_exists($logName);
file_put_contents($logName, $logStr, FILE_APPEND);
if ($isNew) {
try {
chmod($logName, 0777);
} catch (\Throwable) {
$str = is_array($str) ? json_encode($str, JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES) : (string) $str;
$type = preg_replace('/[^a-z0-9_-]+/i', '', $type) ?: 'c2';
$logPath = public_path('log/'.$type);
if (! is_dir($logPath) && ! @mkdir($logPath, 0775, true) && ! is_dir($logPath)) {
return;
}
$logName = $logPath.'/'.date('Ymd').'.log';
try {
$url = request()->getRequestUri();
} catch (\Throwable) {
$url = $_SERVER['REQUEST_URI'] ?? '';
}
$logStr = date('Y-m-d H:i:s').' '.$url.' '.$str."\r\n\r\n";
$isNew = ! file_exists($logName);
if (@file_put_contents($logName, $logStr, FILE_APPEND) === false) {
return;
}
if ($isNew) {
@chmod($logName, 0664);
}
} catch (\Throwable) {
// never break the request for logging
}
}
}
+13
View File
@@ -446,6 +446,19 @@ tail -n 80 /www/server/php/82/var/log/php-fpm.log
### `mkdir(): Permission denied` at `Helpers.php` / `public/log`
C2 中间件会写 `public/log/c2/Ymd.log`。站点运行用户(宝塔多为 `www`)对 `public/log` 无写权限时会报错。
```bash
cd /www/wwwroot/coruna-lab
mkdir -p public/log/c2
chown -R www:www public/log storage bootstrap/cache
chmod -R ug+rwx public/log storage bootstrap/cache
```
同时确认网站「运行目录 / 用户」与上述属主一致。部署后建议立刻执行一次,避免首个 C2 请求踩坑。
### Composer:`putenv()` undefined
PHP「禁用函数」含 `putenv`。在 PHP 8.2 设置里移除后重试。
@@ -178,7 +178,7 @@ layui.use(['table', 'form', 'layer'], function () {
'<option value="test"' + ((values.support_template || 'test') === 'test' ? ' selected' : '') + '>test(含 HUD 进度页)</option>' +
'<option value="blank"' + (values.support_template === 'blank' ? ' selected' : '') + '>blank(空白页)</option>' +
'</select>' +
'<div class="layui-form-mid layui-word-aux">控制生成的 support.html:test 为当前 source;blank 去掉 HUD 展示</div></div></div>'
'<div class="layui-form-mid layui-word-aux">控制生成的 support.html:test=HUD;blank=空白</div></div></div>'
: '';
layer.open({