Container makes /var/lib/pixa usable before starting pixad #161

Merged
clawbot merged 1 commits from issue-159-entrypoint-data-dir into next 2026-09-29 12:44:38 +02:00
Collaborator

Implements #159: no operator step is needed for the data directory.

  • deploy/docker-entrypoint.sh, still running as root, creates /var/lib/pixa if missing. When the directory or one of its top-level entries is not owned by pixad (uid and gid 65532), it gives the directory and everything in it to pixad. It then sets the directory's mode to 750 and runs the server as pixad, as before. The uid, gid and data path are unchanged.
  • README.md "Running under upaas" drops the first-run step and the sentence saying the host directory must exist; it names the container path and links sneak/upaas#235 for upaas creating a missing host directory.

Not in the diff's plain sight: owners are changed with find -depth and chown -h, not chown -R, so the directory itself is changed last (a start stopped part way is finished by the next one) and a symlink is changed itself, never its target.

Run by hand once each:

  • Empty root-owned host directory at /var/lib/pixa: healthy, server running as uid 65532, an image fetched and cached.
  • The same directory holding pixa data owned by uid 1000: healthy, server running as uid 65532, a new image fetched and cached, every entry now owned by 65532.

Judgement call: only the directory and its top-level entries are checked, so a normal start does not walk the cache; something given to another owner deeper down by hand is not noticed.
Not added: a test of the script itself, which would need a root-owned host directory set up in script/docker-smoke.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/pixa/issues/159: no operator step is needed for the data directory. - `deploy/docker-entrypoint.sh`, still running as root, creates `/var/lib/pixa` if missing. When the directory or one of its top-level entries is not owned by `pixad` (uid and gid 65532), it gives the directory and everything in it to `pixad`. It then sets the directory's mode to `750` and runs the server as `pixad`, as before. The uid, gid and data path are unchanged. - `README.md` "Running under upaas" drops the first-run step and the sentence saying the host directory must exist; it names the container path and links https://git.eeqj.de/sneak/upaas/issues/235 for upaas creating a missing host directory. Not in the diff's plain sight: owners are changed with `find -depth` and `chown -h`, not `chown -R`, so the directory itself is changed last (a start stopped part way is finished by the next one) and a symlink is changed itself, never its target. Run by hand once each: - Empty root-owned host directory at `/var/lib/pixa`: healthy, server running as uid 65532, an image fetched and cached. - The same directory holding pixa data owned by uid 1000: healthy, server running as uid 65532, a new image fetched and cached, every entry now owned by 65532. Judgement call: only the directory and its top-level entries are checked, so a normal start does not walk the cache; something given to another owner deeper down by hand is not noticed. Not added: a test of the script itself, which would need a root-owned host directory set up in `script/docker-smoke`. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 11:35:20 +02:00
clawbot self-assigned this 2026-09-29 11:35:20 +02:00
Author
Collaborator

PASS. Checking only the directory and its top-level entries is accepted: data from a run under another uid, and a start stopped part way, always leave a wrong owner at that level.

Model: opus-5-5

PASS. Checking only the directory and its top-level entries is accepted: data from a run under another uid, and a start stopped part way, always leave a wrong owner at that level. Model: opus-5-5
clawbot added 1 commit 2026-09-29 12:32:39 +02:00
The entrypoint now creates /var/lib/pixa if it is missing. When the
directory or one of its top-level entries belongs to another user or
group, it gives the whole tree to pixad (uid and gid 65532); it then
sets the directory's mode to 750 and runs the server as pixad as
before. Data left by a run under another uid is taken over this way.
Only the top level is checked, so a normal start does not walk the
cache; the tree is changed deepest first, so an interrupted start is
finished by the next one.

"Running under upaas" in README.md no longer tells the operator to
create or chown the host directory.

Model: opus-5-5
clawbot force-pushed issue-159-entrypoint-data-dir from bf047df6f4 to 08f8c25349 2026-09-29 12:32:39 +02:00 Compare
clawbot merged commit fd7d7ed205 into next 2026-09-29 12:44:38 +02:00
clawbot deleted branch issue-159-entrypoint-data-dir 2026-09-29 12:44:38 +02:00
clawbot removed the needs-review label 2026-09-29 12:44:38 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#161