Give pixad a fixed uid and gid 65532 (closes #151) #152

Merged
clawbot merged 1 commits from issue-151-fixed-uid into next 2026-09-29 04:44:50 +02:00
Collaborator

Closes #151.

adduser -D gave pixad the first free uid, 1000. Since #129 the container gives a bind-mounted /var/lib/pixa to pixad, so on the host a person's login account (usually uid 1000) ended up owning pixa's database and cache.

The Dockerfile runtime stage now creates the pixad group with gid 65532 and the pixad user with uid 65532 in it. The first-run step of "Running under upaas" in README.md names that uid and gid, so an operator can create the host directory with that owner or leave it to root.

Choice: 65532, the non-root user of the distroless images; above the host login range (1000 to 60000), clear of system accounts (below 1000) and of nobody (65534).

Not changed: deploy/docker-entrypoint.sh names the user only as pixad, so it follows the new uid without edits.

Checked once by hand: on a fresh root-owned host directory (made by a root container) bind-mounted at /var/lib/pixa, the container went healthy, the directory ended up owned by 65532:65532, the server ran as uid and gid 65532, a second container on the same directory answered the first run's image from its cache, and make docker-smoke passed under the lock.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/pixa/issues/151. `adduser -D` gave `pixad` the first free uid, 1000. Since https://git.eeqj.de/sneak/pixa/issues/129 the container gives a bind-mounted `/var/lib/pixa` to `pixad`, so on the host a person's login account (usually uid 1000) ended up owning pixa's database and cache. The `Dockerfile` runtime stage now creates the `pixad` group with gid 65532 and the `pixad` user with uid 65532 in it. The first-run step of "Running under upaas" in `README.md` names that uid and gid, so an operator can create the host directory with that owner or leave it to root. Choice: 65532, the non-root user of the distroless images; above the host login range (1000 to 60000), clear of system accounts (below 1000) and of `nobody` (65534). Not changed: `deploy/docker-entrypoint.sh` names the user only as `pixad`, so it follows the new uid without edits. Checked once by hand: on a fresh root-owned host directory (made by a root container) bind-mounted at `/var/lib/pixa`, the container went healthy, the directory ended up owned by 65532:65532, the server ran as uid and gid 65532, a second container on the same directory answered the first run's image from its cache, and `make docker-smoke` passed under the lock. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 04:15:13 +02:00
clawbot self-assigned this 2026-09-29 04:15:13 +02:00
clawbot added 1 commit 2026-09-29 04:15:14 +02:00
Give pixad a fixed uid and gid 65532 (closes #151)
check / check (push) Successful in 3m17s
3cf8546b2d
adduser took the first free uid, 1000, and the entrypoint gives a
bind-mounted /var/lib/pixa to pixad, so on the host a person's login
account ended up owning pixa's database and cache. The image now creates
the pixad group with gid 65532 and the pixad user with uid 65532, which
host login and system accounts do not use. The first-run step of
"Running under upaas" in README.md names the uid and gid.

Model: opus-5-5
Author
Collaborator

PASS: pixad has uid and gid 65532 in the image, and the first-run step of "Running under upaas" is true of it.

Model: opus-5-5

PASS: `pixad` has uid and gid 65532 in the image, and the first-run step of "Running under upaas" is true of it. Model: opus-5-5
clawbot merged commit ed3f8770e6 into next 2026-09-29 04:44:50 +02:00
clawbot deleted branch issue-151-fixed-uid 2026-09-29 04:44:52 +02:00
clawbot removed the needs-review label 2026-09-29 04:44:52 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#152