Entrypoint checks DATA_DIR in full before acting on it as root (closes #80) #81

Open
clawbot wants to merge 1 commits from fix/entrypoint-data-dir-check into next
Collaborator

Closes #80.

bin/entrypoint.sh, which runs as root, now checks DATA_DIR before it creates anything or changes an owner or mode: first that it is /data or a path below it with no ., .. or empty part, then that no part of the path that exists, /data included, is a symbolic link. Every refusal stops the start with one message naming DATA_DIR. Only then does it create what is missing and set owner and mode. The README section "Running under upaas" says which values are accepted.

What the diff does not show:

  • chown now runs on /data alone, which holds DATA_DIR, with -h: a link in /data is itself given to netwatch, not its target.
  • chmod still follows links. None can appear after the check: nothing else runs in the container yet, and upaas removes the old container before it starts the new one.

Verified by running the image with a bind-mounted host directory: each case in the issue, and /data itself a link (in a test image), stopped the start naming DATA_DIR; comparing every path in the container before and after, the only one created was /etc/nginx/trusted-proxies.conf, which the entrypoint writes before it reaches DATA_DIR, and no owner or mode changed. An empty root-owned directory and one holding another uid's files each turned healthy twice, with the backend running as netwatch and a posted report written.

Judgement call: a file where the path needs a directory still stops the start with mkdir's own error, which names the path, not DATA_DIR.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/netwatch/issues/80. `bin/entrypoint.sh`, which runs as root, now checks `DATA_DIR` before it creates anything or changes an owner or mode: first that it is `/data` or a path below it with no `.`, `..` or empty part, then that no part of the path that exists, `/data` included, is a symbolic link. Every refusal stops the start with one message naming `DATA_DIR`. Only then does it create what is missing and set owner and mode. The README section "Running under upaas" says which values are accepted. What the diff does not show: - `chown` now runs on `/data` alone, which holds `DATA_DIR`, with `-h`: a link in `/data` is itself given to `netwatch`, not its target. - `chmod` still follows links. None can appear after the check: nothing else runs in the container yet, and upaas removes the old container before it starts the new one. Verified by running the image with a bind-mounted host directory: each case in the issue, and `/data` itself a link (in a test image), stopped the start naming `DATA_DIR`; comparing every path in the container before and after, the only one created was `/etc/nginx/trusted-proxies.conf`, which the entrypoint writes before it reaches `DATA_DIR`, and no owner or mode changed. An empty root-owned directory and one holding another uid's files each turned healthy twice, with the backend running as `netwatch` and a posted report written. Judgement call: a file where the path needs a directory still stops the start with `mkdir`'s own error, which names the path, not `DATA_DIR`. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 12:59:46 +02:00
clawbot self-assigned this 2026-09-29 12:59:46 +02:00
clawbot added 1 commit 2026-09-29 12:59:46 +02:00
`bin/entrypoint.sh` now checks `DATA_DIR` before it creates anything or
changes an owner or mode: it must be `/data` or a path below it with no
`.`, `..` or empty part, and no part of it that exists, `/data`
included, may be a symbolic link. Anything else stops the start with one
message naming `DATA_DIR`. Only then does it create `DATA_DIR`, give
`/data` and everything in it to `netwatch` (`chown -R -h`, so a link in
it is not followed) and set mode 750 on `/data` and `DATA_DIR`. The
README section "Running under upaas" says which values are accepted.

Model: opus-5-5
Some required checks failed
check / check (push) Failing after 12m54s
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin fix/entrypoint-data-dir-check:fix/entrypoint-data-dir-check
git checkout fix/entrypoint-data-dir-check
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/netwatch#81