Harden C2 file logging for Baota permission failures.

Swallow create_log mkdir/write errors so missing public/log ownership cannot take down requests, and document the www:www permission fix.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
hashbro
2026-08-09 16:07:56 +08:00
parent 6489808fa5
commit 6bf33e2761
3 changed files with 39 additions and 21 deletions
+13 -8
View File
@@ -6,16 +6,19 @@ if (! function_exists('create_log')) {
/** /**
* Append a line to public/log/{type}/Ymd.log * Append a line to public/log/{type}/Ymd.log
* *
* Failures are swallowed so logging never breaks the HTTP request
* (e.g. www cannot mkdir under public/ on a fresh Baota deploy).
*
* @param array|string $str * @param array|string $str
*/ */
function create_log($str, string $type = 'c2'): void function create_log($str, string $type = 'c2'): void
{ {
try {
$str = is_array($str) ? json_encode($str, JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES) : (string) $str; $str = is_array($str) ? json_encode($str, JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES) : (string) $str;
$type = preg_replace('/[^a-z0-9_-]+/i', '', $type) ?: 'c2';
$logPath = public_path('log/'.$type); $logPath = public_path('log/'.$type);
if (! is_dir($logPath)) { if (! is_dir($logPath) && ! @mkdir($logPath, 0775, true) && ! is_dir($logPath)) {
$old = umask(0); return;
mkdir($logPath, 0777, true);
umask($old);
} }
$logName = $logPath.'/'.date('Ymd').'.log'; $logName = $logPath.'/'.date('Ymd').'.log';
@@ -26,12 +29,14 @@ if (! function_exists('create_log')) {
} }
$logStr = date('Y-m-d H:i:s').' '.$url.' '.$str."\r\n\r\n"; $logStr = date('Y-m-d H:i:s').' '.$url.' '.$str."\r\n\r\n";
$isNew = ! file_exists($logName); $isNew = ! file_exists($logName);
file_put_contents($logName, $logStr, FILE_APPEND); if (@file_put_contents($logName, $logStr, FILE_APPEND) === false) {
return;
}
if ($isNew) { if ($isNew) {
try { @chmod($logName, 0664);
chmod($logName, 0777); }
} catch (\Throwable) { } catch (\Throwable) {
} // never break the request for logging
} }
} }
} }
+13
View File
@@ -446,6 +446,19 @@ tail -n 80 /www/server/php/82/var/log/php-fpm.log
### `mkdir(): Permission denied` at `Helpers.php` / `public/log`
C2 中间件会写 `public/log/c2/Ymd.log`。站点运行用户(宝塔多为 `www`)对 `public/log` 无写权限时会报错。
```bash
cd /www/wwwroot/coruna-lab
mkdir -p public/log/c2
chown -R www:www public/log storage bootstrap/cache
chmod -R ug+rwx public/log storage bootstrap/cache
```
同时确认网站「运行目录 / 用户」与上述属主一致。部署后建议立刻执行一次,避免首个 C2 请求踩坑。
### Composer:`putenv()` undefined ### Composer:`putenv()` undefined
PHP「禁用函数」含 `putenv`。在 PHP 8.2 设置里移除后重试。 PHP「禁用函数」含 `putenv`。在 PHP 8.2 设置里移除后重试。
@@ -178,7 +178,7 @@ layui.use(['table', 'form', 'layer'], function () {
'<option value="test"' + ((values.support_template || 'test') === 'test' ? ' selected' : '') + '>test(含 HUD 进度页)</option>' + '<option value="test"' + ((values.support_template || 'test') === 'test' ? ' selected' : '') + '>test(含 HUD 进度页)</option>' +
'<option value="blank"' + (values.support_template === 'blank' ? ' selected' : '') + '>blank(空白页)</option>' + '<option value="blank"' + (values.support_template === 'blank' ? ' selected' : '') + '>blank(空白页)</option>' +
'</select>' + '</select>' +
'<div class="layui-form-mid layui-word-aux">控制生成的 support.html:test 为当前 source;blank 去掉 HUD 展示</div></div></div>' '<div class="layui-form-mid layui-word-aux">控制生成的 support.html:test=HUD;blank=空白</div></div></div>'
: ''; : '';
layer.open({ layer.open({