Dockerfile creates the pixad user with adduser -D, which takes the first free uid, 1000. Since #129, the container gives a root-owned /var/lib/pixa host directory to pixad on first start. On the host, uid 1000 is usually the first person's login account, which then owns pixa's database and cached images and can rewrite them.
Definition of done
pixad gets a fixed uid and gid that host login accounts and common system accounts do not use (for example 65532, as the widely used distroless images do); state the choice in one line in the PR.
README.md "Running under upaas", first-run step, names the uid and gid, so an operator can create the host directory with that owner.
The container still starts on a fresh root-owned directory, a second run keeps the first run's state, and make docker-smoke passes; checked once by hand, one line in the PR body.
Model: opus-5-5
Found in the release review of https://git.eeqj.de/sneak/pixa/pulls/147 (https://git.eeqj.de/sneak/pixa/pulls/147#issuecomment-105251, finding 2).
`Dockerfile` creates the `pixad` user with `adduser -D`, which takes the first free uid, 1000. Since https://git.eeqj.de/sneak/pixa/issues/129, the container gives a root-owned `/var/lib/pixa` host directory to `pixad` on first start. On the host, uid 1000 is usually the first person's login account, which then owns pixa's database and cached images and can rewrite them.
## Definition of done
- `pixad` gets a fixed uid and gid that host login accounts and common system accounts do not use (for example 65532, as the widely used distroless images do); state the choice in one line in the PR.
- `README.md` "Running under upaas", first-run step, names the uid and gid, so an operator can create the host directory with that owner.
- The container still starts on a fresh root-owned directory, a second run keeps the first run's state, and `make docker-smoke` passes; checked once by hand, one line in the PR body.
Model: opus-5-5
clawbot
added this to the 1.0.0 milestone 2026-09-29 04:08:24 +02:00
clawbot
self-assigned this 2026-09-29 04:08:24 +02:00
Plan: the Dockerfile runtime stage creates the pixad group with gid 65532 and the pixad user with uid 65532 in that group, instead of taking the first free uid (1000).
Why 65532: host login accounts get uids from 1000 up to 60000 and system accounts stay below 1000, so neither lands on it; 65534 is nobody, which must not own pixa's files either; and 65532 is the non-root user of the widely used distroless images, so an operator may already recognise it.
deploy/docker-entrypoint.sh names the user only as pixad, so it needs no change. The first-run step of "Running under upaas" in README.md will name uid and gid 65532.
Model: opus-5-5
Plan: the `Dockerfile` runtime stage creates the `pixad` group with gid 65532 and the `pixad` user with uid 65532 in that group, instead of taking the first free uid (1000).
Why 65532: host login accounts get uids from 1000 up to 60000 and system accounts stay below 1000, so neither lands on it; 65534 is `nobody`, which must not own pixa's files either; and 65532 is the non-root user of the widely used distroless images, so an operator may already recognise it.
`deploy/docker-entrypoint.sh` names the user only as `pixad`, so it needs no change. The first-run step of "Running under upaas" in `README.md` will name uid and gid 65532.
Model: opus-5-5
Built as planned in #152: pixad is uid and gid 65532 in the image, and the first-run step of "Running under upaas" names them.
Model: opus-5-5
Built as planned in https://git.eeqj.de/sneak/pixa/pulls/152: `pixad` is uid and gid 65532 in the image, and the first-run step of "Running under upaas" names them.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found in the release review of #147 (#147 (comment), finding 2).
Dockerfilecreates thepixaduser withadduser -D, which takes the first free uid, 1000. Since #129, the container gives a root-owned/var/lib/pixahost directory topixadon first start. On the host, uid 1000 is usually the first person's login account, which then owns pixa's database and cached images and can rewrite them.Definition of done
pixadgets a fixed uid and gid that host login accounts and common system accounts do not use (for example 65532, as the widely used distroless images do); state the choice in one line in the PR.README.md"Running under upaas", first-run step, names the uid and gid, so an operator can create the host directory with that owner.make docker-smokepasses; checked once by hand, one line in the PR body.Model: opus-5-5
Plan: the
Dockerfileruntime stage creates thepixadgroup with gid 65532 and thepixaduser with uid 65532 in that group, instead of taking the first free uid (1000).Why 65532: host login accounts get uids from 1000 up to 60000 and system accounts stay below 1000, so neither lands on it; 65534 is
nobody, which must not own pixa's files either; and 65532 is the non-root user of the widely used distroless images, so an operator may already recognise it.deploy/docker-entrypoint.shnames the user only aspixad, so it needs no change. The first-run step of "Running under upaas" inREADME.mdwill name uid and gid 65532.Model: opus-5-5
Built as planned in #152:
pixadis uid and gid 65532 in the image, and the first-run step of "Running under upaas" names them.Model: opus-5-5