Container sets up its own data directory (closes #75) #76

Merged
sneak merged 1 commits from fix/data-dir-permissions into next 2026-09-29 12:04:00 +02:00
Collaborator

Closes #75.

bin/entrypoint.sh, which already runs as root, now makes the data directory usable before the backend starts: it creates DATA_DIR if missing, gives it and /data to the netwatch user (chown -R), and sets mode 750 on both, the mode the backend gives a directory it creates. The backend still runs as netwatch. The README "Running under upaas" section loses its first-run step that created and chowned the host directory and names only the path to mount. The Dockerfile's build-time mkdir and chown of /data are gone, since the entrypoint now does this on every start.

What the diff does not show:

  • The host directory mounted at /data ends up owned by uid 1000 with mode 750, and everything under DATA_DIR is chowned to uid 1000 on every start.
  • If the directory cannot be created or chowned, the container stops with that tool's error before either process starts.

Recorded runs with --mount type=bind: an empty directory owned by root (mode 755, and again mode 700), and one holding a reports directory and report file owned by uid 1001 with mode 700. Each time the container turned healthy, netwatch-server ran as netwatch, and a posted report was written to DATA_DIR; a second start on the root-owned and the uid 1001 directories did the same.

Judgement call: /data itself is given to netwatch as well as DATA_DIR, so the backend can reach DATA_DIR inside a host directory with mode 700.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/netwatch/issues/75. `bin/entrypoint.sh`, which already runs as root, now makes the data directory usable before the backend starts: it creates `DATA_DIR` if missing, gives it and `/data` to the `netwatch` user (`chown -R`), and sets mode 750 on both, the mode the backend gives a directory it creates. The backend still runs as `netwatch`. The README "Running under upaas" section loses its first-run step that created and chowned the host directory and names only the path to mount. The Dockerfile's build-time `mkdir` and `chown` of `/data` are gone, since the entrypoint now does this on every start. What the diff does not show: - The host directory mounted at `/data` ends up owned by uid 1000 with mode 750, and everything under `DATA_DIR` is chowned to uid 1000 on every start. - If the directory cannot be created or chowned, the container stops with that tool's error before either process starts. Recorded runs with `--mount type=bind`: an empty directory owned by root (mode 755, and again mode 700), and one holding a `reports` directory and report file owned by uid 1001 with mode 700. Each time the container turned healthy, `netwatch-server` ran as `netwatch`, and a posted report was written to `DATA_DIR`; a second start on the root-owned and the uid 1001 directories did the same. Judgement call: `/data` itself is given to `netwatch` as well as `DATA_DIR`, so the backend can reach `DATA_DIR` inside a host directory with mode 700. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 11:21:45 +02:00
clawbot self-assigned this 2026-09-29 11:21:45 +02:00
Author
Collaborator
  1. bin/entrypoint.sh line 72, chmod 750 /data "$DATA_DIR": chmod follows a symbolic link. DATA_DIR is /data/reports by default, inside /data, which the netwatch user owns after the first start. So when it is a symbolic link to a directory, the entrypoint, running as root, sets mode 750 on that directory, wherever it is in the container. With /data/reports linked to /etc, /etc ends up at mode 750. A link to /usr/share/nginx/html would stop nginx serving the frontend while the health check still passes. The chown -R on line 71 does not follow links. Acceptable: the entrypoint never changes a mode through a symbolic link. For example, it stops with an error naming DATA_DIR when DATA_DIR is a symbolic link.

Model: opus-5-5

1. `bin/entrypoint.sh` line 72, `chmod 750 /data "$DATA_DIR"`: `chmod` follows a symbolic link. `DATA_DIR` is `/data/reports` by default, inside `/data`, which the `netwatch` user owns after the first start. So when it is a symbolic link to a directory, the entrypoint, running as root, sets mode 750 on that directory, wherever it is in the container. With `/data/reports` linked to `/etc`, `/etc` ends up at mode 750. A link to `/usr/share/nginx/html` would stop nginx serving the frontend while the health check still passes. The `chown -R` on line 71 does not follow links. Acceptable: the entrypoint never changes a mode through a symbolic link. For example, it stops with an error naming `DATA_DIR` when `DATA_DIR` is a symbolic link. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-09-29 11:55:53 +02:00
clawbot added 1 commit 2026-09-29 11:59:51 +02:00
bin/entrypoint.sh, still running as root, now creates DATA_DIR if
missing and gives it and /data to the netwatch user with mode 750
before starting the backend as that user. It stops the start instead
when a symbolic link is on the path to /data or DATA_DIR, since chown
and chmod would change what the link points to. An empty host
directory owned by root, or one holding files from another uid, works
with no step on the host, so the README no longer tells the operator
to create or chown it. The image no longer sets that ownership at
build time.

Model: opus-5-5
clawbot force-pushed fix/data-dir-permissions from 7d31f514e3 to 3a335bbabe 2026-09-29 11:59:51 +02:00 Compare
sneak merged commit a5ca73c585 into next 2026-09-29 12:04:00 +02:00
sneak deleted branch fix/data-dir-permissions 2026-09-29 12:04:00 +02:00
clawbot removed the needs-rework label 2026-09-29 12:06:53 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/netwatch#76