cmake install directory without OWNER_WRITE

Viewed 284

I have a generic Component template that shall install different projects in the following manner:

/path/to/Components/<COMPONENT_NAME>/<COMPONENT_VERSION>/CONTENTS

My install rule in CMakeLists.txt looks like that:

install(TARGETS ${TARGET_NAME} DESTINATION lib PERMISSIONS ${FILE_PERMISSIONS})
install(FILES include/${TARGET_NAME}.h DESTINATION include PERMISSIONS ${FILE_PERMISSIONS}

By setting PERMISSIONS only, directories that are created by the install rule will have the umask of the system. Using the directory option of install is no fit for my usecase, as i only intend to install single/specific files (expecially in the include directory). I found a very great description/bugreport of the behavior. https://gitlab.kitware.com/cmake/cmake/-/issues/9620

With that new information i managed to set the CMAKE_INSTALL_DEFAULT_DIRECTORY_PERMISSIONS which resolves that issue in parts, but not fully. The thing is the installed directories shall have read and execute acces and no write access for user, group or others.

By setting :

set (CMAKE_INSTALL_DEFAULT_DIRECTORY_PERMISSIONS OWNER_READ OWNER_EXECUTE GROUP_READ GROUP_EXECUTE)

I'm not allowed anymore to create the subfolders/files inside the directory tree.

So the question is: Is there an option in cmake that installs the component (in userspace without root/admin privileges) and leaves the whole directory structure (of the newly created dirs) as OWNER_READ OWNER_EXECUTE GROUP_READ GROUP_EXECUTE only? Basically it shall set write access on the directories while installing and end with setting the directories to the specified access flags.

1 Answers

So the question is: Is there an option in cmake that installs the component (in userspace without root/admin privileges) and leaves the whole directory structure (of the newly created dirs) as OWNER_READ OWNER_EXECUTE GROUP_READ GROUP_EXECUTE only? Basically it shall set write access on the directories while installing and end with setting the directories to the specified access flags.

As you observe, you cannot create the directories initially unwritable, for then you cannot install files within. On the contrary, if there is any question about it then as a preliminary installation step, you must ensure that the ultimate target directory, at least, is writable.

It is very unusual for files and directories to have modes that deny write access to the owner, however, for that has very little useful effect. The owner can change the modes of their own files at will, regardless of current mode, and in some cases they can override the mode without actually changing it. You really, then, should consider just abandoning the plan.

But if you want to go ahead, then the only way I see is to have a separate installation action that modifies the permissions of the directories as you want, after all wanted files have been installed within. You can set up custom install logic such as this in CMake with install(SCRIPT) or install(CODE), and implement the details with execute_process(). The latter has OS-specific aspects, so you will need separate alternatives for Windows and Unix-y systems, if indeed you are trying to support all of the above.

Related