From 3cf8546b2d2421452857fcf020218cd6d816d09e Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Tue, 29 Sep 2026 02:10:08 +0000 Subject: [PATCH] Give pixad a fixed uid and gid 65532 (closes #151) adduser took the first free uid, 1000, and the entrypoint gives a bind-mounted /var/lib/pixa to pixad, so on the host a person's login account ended up owning pixa's database and cache. The image now creates the pixad group with gid 65532 and the pixad user with uid 65532, which host login and system accounts do not use. The first-run step of "Running under upaas" in README.md names the uid and gid. Model: opus-5-5 --- Dockerfile | 8 ++++++-- README.md | 6 ++++-- TODO.md | 5 +++++ 3 files changed, 15 insertions(+), 4 deletions(-) diff --git a/Dockerfile b/Dockerfile index 77510a0..45027be 100644 --- a/Dockerfile +++ b/Dockerfile @@ -68,8 +68,12 @@ RUN apk add --no-cache \ COPY --from=builder /pixad /usr/local/bin/pixad COPY deploy/docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh -# Create non-root user, config directory, and data directory -RUN adduser -D -H -s /sbin/nologin pixad && \ +# Create non-root user, config directory, and data directory. pixad +# gets uid and gid 65532, which host login and system accounts do not +# use: a bind-mounted /var/lib/pixa is given to pixad, and on the host +# it must not belong to a person's account. +RUN addgroup -g 65532 pixad && \ + adduser -D -H -s /sbin/nologin -u 65532 -G pixad pixad && \ mkdir -p /var/lib/pixa /etc/pixa && \ chown pixad:pixad /var/lib/pixa diff --git a/README.md b/README.md index 23fe41b..ec673d1 100644 --- a/README.md +++ b/README.md @@ -58,8 +58,10 @@ What the [upaas](https://git.eeqj.de/sneak/upaas) app for pixa needs: `healthy`. The probe uses the port from `PORT` (default `8080`), so a port changed only in a mounted config file is not seen by it: change the port with `PORT`. -- **First run:** create the host directory. It may be owned by root: the - container gives it to its `pixad` user when it starts. +- **First run:** create the host directory, owned by root or by uid + `65532` and gid `65532`. The server runs as the container's `pixad` + user, which has that uid and gid, and the container gives the + directory to `pixad` when it starts. ## Rationale diff --git a/TODO.md b/TODO.md index c10609b..a8ec7c3 100644 --- a/TODO.md +++ b/TODO.md @@ -30,6 +30,11 @@ exhaustion # Completed Steps +- 2026-09-29 fixed uid and gid for `pixad` (closes #151): the image creates the + `pixad` group with gid 65532 and the `pixad` user with uid 65532, instead of + the first free uid 1000, so a bind-mounted `/var/lib/pixa` given to `pixad` + is not owned on the host by a person's login account; the first-run step of + "Running under upaas" in `README.md` names the uid and gid. - 2026-09-29 `max-age` never outlives an expiring URL (closes #63): both image routes build `Cache-Control` from the request's `Expires`, which an encrypted URL's expiry now fills too; `max-age` is one year, or the whole seconds left -- 2.54.0