bin/entrypoint.sh, which already runs as root, now makes the data directory usable before the backend starts: it creates DATA_DIR if missing, gives it and /data to the netwatch user (chown -R), and sets mode 750 on both, the mode the backend gives a directory it creates. The backend still runs as netwatch. The README "Running under upaas" section loses its first-run step that created and chowned the host directory and names only the path to mount. The Dockerfile's build-time mkdir and chown of /data are gone, since the entrypoint now does this on every start.
What the diff does not show:
The host directory mounted at /data ends up owned by uid 1000 with mode 750, and everything under DATA_DIR is chowned to uid 1000 on every start.
If the directory cannot be created or chowned, the container stops with that tool's error before either process starts.
Recorded runs with --mount type=bind: an empty directory owned by root (mode 755, and again mode 700), and one holding a reports directory and report file owned by uid 1001 with mode 700. Each time the container turned healthy, netwatch-server ran as netwatch, and a posted report was written to DATA_DIR; a second start on the root-owned and the uid 1001 directories did the same.
Judgement call: /data itself is given to netwatch as well as DATA_DIR, so the backend can reach DATA_DIR inside a host directory with mode 700.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/netwatch/issues/75.
`bin/entrypoint.sh`, which already runs as root, now makes the data directory usable before the backend starts: it creates `DATA_DIR` if missing, gives it and `/data` to the `netwatch` user (`chown -R`), and sets mode 750 on both, the mode the backend gives a directory it creates. The backend still runs as `netwatch`. The README "Running under upaas" section loses its first-run step that created and chowned the host directory and names only the path to mount. The Dockerfile's build-time `mkdir` and `chown` of `/data` are gone, since the entrypoint now does this on every start.
What the diff does not show:
- The host directory mounted at `/data` ends up owned by uid 1000 with mode 750, and everything under `DATA_DIR` is chowned to uid 1000 on every start.
- If the directory cannot be created or chowned, the container stops with that tool's error before either process starts.
Recorded runs with `--mount type=bind`: an empty directory owned by root (mode 755, and again mode 700), and one holding a `reports` directory and report file owned by uid 1001 with mode 700. Each time the container turned healthy, `netwatch-server` ran as `netwatch`, and a posted report was written to `DATA_DIR`; a second start on the root-owned and the uid 1001 directories did the same.
Judgement call: `/data` itself is given to `netwatch` as well as `DATA_DIR`, so the backend can reach `DATA_DIR` inside a host directory with mode 700.
Model: opus-5-5
bin/entrypoint.sh line 72, chmod 750 /data "$DATA_DIR": chmod follows a symbolic link. DATA_DIR is /data/reports by default, inside /data, which the netwatch user owns after the first start. So when it is a symbolic link to a directory, the entrypoint, running as root, sets mode 750 on that directory, wherever it is in the container. With /data/reports linked to /etc, /etc ends up at mode 750. A link to /usr/share/nginx/html would stop nginx serving the frontend while the health check still passes. The chown -R on line 71 does not follow links. Acceptable: the entrypoint never changes a mode through a symbolic link. For example, it stops with an error naming DATA_DIR when DATA_DIR is a symbolic link.
Model: opus-5-5
1. `bin/entrypoint.sh` line 72, `chmod 750 /data "$DATA_DIR"`: `chmod` follows a symbolic link. `DATA_DIR` is `/data/reports` by default, inside `/data`, which the `netwatch` user owns after the first start. So when it is a symbolic link to a directory, the entrypoint, running as root, sets mode 750 on that directory, wherever it is in the container. With `/data/reports` linked to `/etc`, `/etc` ends up at mode 750. A link to `/usr/share/nginx/html` would stop nginx serving the frontend while the health check still passes. The `chown -R` on line 71 does not follow links. Acceptable: the entrypoint never changes a mode through a symbolic link. For example, it stops with an error naming `DATA_DIR` when `DATA_DIR` is a symbolic link.
Model: opus-5-5
bin/entrypoint.sh, still running as root, now creates DATA_DIR if
missing and gives it and /data to the netwatch user with mode 750
before starting the backend as that user. It stops the start instead
when a symbolic link is on the path to /data or DATA_DIR, since chown
and chmod would change what the link points to. An empty host
directory owned by root, or one holding files from another uid, works
with no step on the host, so the README no longer tells the operator
to create or chown it. The image no longer sets that ownership at
build time.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #75.
bin/entrypoint.sh, which already runs as root, now makes the data directory usable before the backend starts: it createsDATA_DIRif missing, gives it and/datato thenetwatchuser (chown -R), and sets mode 750 on both, the mode the backend gives a directory it creates. The backend still runs asnetwatch. The README "Running under upaas" section loses its first-run step that created and chowned the host directory and names only the path to mount. The Dockerfile's build-timemkdirandchownof/dataare gone, since the entrypoint now does this on every start.What the diff does not show:
/dataends up owned by uid 1000 with mode 750, and everything underDATA_DIRis chowned to uid 1000 on every start.Recorded runs with
--mount type=bind: an empty directory owned by root (mode 755, and again mode 700), and one holding areportsdirectory and report file owned by uid 1001 with mode 700. Each time the container turned healthy,netwatch-serverran asnetwatch, and a posted report was written toDATA_DIR; a second start on the root-owned and the uid 1001 directories did the same.Judgement call:
/dataitself is given tonetwatchas well asDATA_DIR, so the backend can reachDATA_DIRinside a host directory with mode 700.Model: opus-5-5
bin/entrypoint.shline 72,chmod 750 /data "$DATA_DIR":chmodfollows a symbolic link.DATA_DIRis/data/reportsby default, inside/data, which thenetwatchuser owns after the first start. So when it is a symbolic link to a directory, the entrypoint, running as root, sets mode 750 on that directory, wherever it is in the container. With/data/reportslinked to/etc,/etcends up at mode 750. A link to/usr/share/nginx/htmlwould stop nginx serving the frontend while the health check still passes. Thechown -Ron line 71 does not follow links. Acceptable: the entrypoint never changes a mode through a symbolic link. For example, it stops with an error namingDATA_DIRwhenDATA_DIRis a symbolic link.Model: opus-5-5
7d31f514e3to3a335bbabe