bin/entrypoint.sh, which runs as root, now checks DATA_DIR before it creates anything or changes an owner or mode: first that it is /data or a path below it with no ., .. or empty part, then that no part of the path that exists, /data included, is a symbolic link. Every refusal stops the start with one message naming DATA_DIR. Only then does it create what is missing and set owner and mode. The README section "Running under upaas" says which values are accepted.
What the diff does not show:
chown now runs on /data alone, which holds DATA_DIR, with -h: a link in /data is itself given to netwatch, not its target.
chmod still follows links. None can appear after the check: nothing else runs in the container yet, and upaas removes the old container before it starts the new one.
Verified by running the image with a bind-mounted host directory: each case in the issue, and /data itself a link (in a test image), stopped the start naming DATA_DIR; comparing every path in the container before and after, the only one created was /etc/nginx/trusted-proxies.conf, which the entrypoint writes before it reaches DATA_DIR, and no owner or mode changed. An empty root-owned directory and one holding another uid's files each turned healthy twice, with the backend running as netwatch and a posted report written.
Judgement call: a file where the path needs a directory still stops the start with mkdir's own error, which names the path, not DATA_DIR.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/netwatch/issues/80.
`bin/entrypoint.sh`, which runs as root, now checks `DATA_DIR` before it creates anything or changes an owner or mode: first that it is `/data` or a path below it with no `.`, `..` or empty part, then that no part of the path that exists, `/data` included, is a symbolic link. Every refusal stops the start with one message naming `DATA_DIR`. Only then does it create what is missing and set owner and mode. The README section "Running under upaas" says which values are accepted.
What the diff does not show:
- `chown` now runs on `/data` alone, which holds `DATA_DIR`, with `-h`: a link in `/data` is itself given to `netwatch`, not its target.
- `chmod` still follows links. None can appear after the check: nothing else runs in the container yet, and upaas removes the old container before it starts the new one.
Verified by running the image with a bind-mounted host directory: each case in the issue, and `/data` itself a link (in a test image), stopped the start naming `DATA_DIR`; comparing every path in the container before and after, the only one created was `/etc/nginx/trusted-proxies.conf`, which the entrypoint writes before it reaches `DATA_DIR`, and no owner or mode changed. An empty root-owned directory and one holding another uid's files each turned healthy twice, with the backend running as `netwatch` and a posted report written.
Judgement call: a file where the path needs a directory still stops the start with `mkdir`'s own error, which names the path, not `DATA_DIR`.
Model: opus-5-5
`bin/entrypoint.sh` now checks `DATA_DIR` before it creates anything or
changes an owner or mode: it must be `/data` or a path below it with no
`.`, `..` or empty part, and no part of it that exists, `/data`
included, may be a symbolic link. Anything else stops the start with one
message naming `DATA_DIR`. Only then does it create `DATA_DIR`, give
`/data` and everything in it to `netwatch` (`chown -R -h`, so a link in
it is not followed) and set mode 750 on `/data` and `DATA_DIR`. The
README section "Running under upaas" says which values are accepted.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #80.
bin/entrypoint.sh, which runs as root, now checksDATA_DIRbefore it creates anything or changes an owner or mode: first that it is/dataor a path below it with no.,..or empty part, then that no part of the path that exists,/dataincluded, is a symbolic link. Every refusal stops the start with one message namingDATA_DIR. Only then does it create what is missing and set owner and mode. The README section "Running under upaas" says which values are accepted.What the diff does not show:
chownnow runs on/dataalone, which holdsDATA_DIR, with-h: a link in/datais itself given tonetwatch, not its target.chmodstill follows links. None can appear after the check: nothing else runs in the container yet, and upaas removes the old container before it starts the new one.Verified by running the image with a bind-mounted host directory: each case in the issue, and
/dataitself a link (in a test image), stopped the start namingDATA_DIR; comparing every path in the container before and after, the only one created was/etc/nginx/trusted-proxies.conf, which the entrypoint writes before it reachesDATA_DIR, and no owner or mode changed. An empty root-owned directory and one holding another uid's files each turned healthy twice, with the backend running asnetwatchand a posted report written.Judgement call: a file where the path needs a directory still stops the start with
mkdir's own error, which names the path, notDATA_DIR.Model: opus-5-5
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.