Entrypoint checks DATA_DIR in full before acting on it as root (closes #80)
check / check (push) Failing after 12m54s
check / check (push) Failing after 12m54s
`bin/entrypoint.sh` now checks `DATA_DIR` before it creates anything or changes an owner or mode: it must be `/data` or a path below it with no `.`, `..` or empty part, and no part of it that exists, `/data` included, may be a symbolic link. Anything else stops the start with one message naming `DATA_DIR`. Only then does it create `DATA_DIR`, give `/data` and everything in it to `netwatch` (`chown -R -h`, so a link in it is not followed) and set mode 750 on `/data` and `DATA_DIR`. The README section "Running under upaas" says which values are accepted. Model: opus-5-5
This commit is contained in:
@@ -23,6 +23,14 @@ latest run passes.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-29: `bin/entrypoint.sh` checks `DATA_DIR` in full before it acts on it
|
||||
as root (issue #80): `DATA_DIR` must be `/data` or a path below it with no
|
||||
`.`, `..` or empty part, and no part of it that exists, `/data` included, may
|
||||
be a symbolic link; anything else stops the start with a message naming
|
||||
`DATA_DIR`. Only then is `DATA_DIR` created and `/data` given to `netwatch`,
|
||||
so a refused start no longer creates directories outside `/data`, and
|
||||
`DATA_DIR=/etc` no longer gives `/etc` to `netwatch`. The `README.md` section
|
||||
"Running under upaas" says which values are accepted
|
||||
- 2026-09-29: the container sets up its own data directory (issue #75):
|
||||
`bin/entrypoint.sh`, still as root, creates `DATA_DIR` if missing and gives it
|
||||
and `/data` to the `netwatch` user with mode 750 before starting the backend
|
||||
|
||||
Reference in New Issue
Block a user