Implements #159: no operator step is needed for the data directory.
deploy/docker-entrypoint.sh, still running as root, creates /var/lib/pixa if missing. When the directory or one of its top-level entries is not owned by pixad (uid and gid 65532), it gives the directory and everything in it to pixad. It then sets the directory's mode to 750 and runs the server as pixad, as before. The uid, gid and data path are unchanged.
README.md "Running under upaas" drops the first-run step and the sentence saying the host directory must exist; it names the container path and links sneak/upaas#235 for upaas creating a missing host directory.
Not in the diff's plain sight: owners are changed with find -depth and chown -h, not chown -R, so the directory itself is changed last (a start stopped part way is finished by the next one) and a symlink is changed itself, never its target.
Run by hand once each:
Empty root-owned host directory at /var/lib/pixa: healthy, server running as uid 65532, an image fetched and cached.
The same directory holding pixa data owned by uid 1000: healthy, server running as uid 65532, a new image fetched and cached, every entry now owned by 65532.
Judgement call: only the directory and its top-level entries are checked, so a normal start does not walk the cache; something given to another owner deeper down by hand is not noticed.
Not added: a test of the script itself, which would need a root-owned host directory set up in script/docker-smoke.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/pixa/issues/159: no operator step is needed for the data directory.
- `deploy/docker-entrypoint.sh`, still running as root, creates `/var/lib/pixa` if missing. When the directory or one of its top-level entries is not owned by `pixad` (uid and gid 65532), it gives the directory and everything in it to `pixad`. It then sets the directory's mode to `750` and runs the server as `pixad`, as before. The uid, gid and data path are unchanged.
- `README.md` "Running under upaas" drops the first-run step and the sentence saying the host directory must exist; it names the container path and links https://git.eeqj.de/sneak/upaas/issues/235 for upaas creating a missing host directory.
Not in the diff's plain sight: owners are changed with `find -depth` and `chown -h`, not `chown -R`, so the directory itself is changed last (a start stopped part way is finished by the next one) and a symlink is changed itself, never its target.
Run by hand once each:
- Empty root-owned host directory at `/var/lib/pixa`: healthy, server running as uid 65532, an image fetched and cached.
- The same directory holding pixa data owned by uid 1000: healthy, server running as uid 65532, a new image fetched and cached, every entry now owned by 65532.
Judgement call: only the directory and its top-level entries are checked, so a normal start does not walk the cache; something given to another owner deeper down by hand is not noticed.
Not added: a test of the script itself, which would need a root-owned host directory set up in `script/docker-smoke`.
Model: opus-5-5
PASS. Checking only the directory and its top-level entries is accepted: data from a run under another uid, and a start stopped part way, always leave a wrong owner at that level.
Model: opus-5-5
PASS. Checking only the directory and its top-level entries is accepted: data from a run under another uid, and a start stopped part way, always leave a wrong owner at that level.
Model: opus-5-5
The entrypoint now creates /var/lib/pixa if it is missing. When the
directory or one of its top-level entries belongs to another user or
group, it gives the whole tree to pixad (uid and gid 65532); it then
sets the directory's mode to 750 and runs the server as pixad as
before. Data left by a run under another uid is taken over this way.
Only the top level is checked, so a normal start does not walk the
cache; the tree is changed deepest first, so an interrupted start is
finished by the next one.
"Running under upaas" in README.md no longer tells the operator to
create or chown the host directory.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #159: no operator step is needed for the data directory.
deploy/docker-entrypoint.sh, still running as root, creates/var/lib/pixaif missing. When the directory or one of its top-level entries is not owned bypixad(uid and gid 65532), it gives the directory and everything in it topixad. It then sets the directory's mode to750and runs the server aspixad, as before. The uid, gid and data path are unchanged.README.md"Running under upaas" drops the first-run step and the sentence saying the host directory must exist; it names the container path and links sneak/upaas#235 for upaas creating a missing host directory.Not in the diff's plain sight: owners are changed with
find -depthandchown -h, notchown -R, so the directory itself is changed last (a start stopped part way is finished by the next one) and a symlink is changed itself, never its target.Run by hand once each:
/var/lib/pixa: healthy, server running as uid 65532, an image fetched and cached.Judgement call: only the directory and its top-level entries are checked, so a normal start does not walk the cache; something given to another owner deeper down by hand is not noticed.
Not added: a test of the script itself, which would need a root-owned host directory set up in
script/docker-smoke.Model: opus-5-5
PASS. Checking only the directory and its top-level entries is accepted: data from a run under another uid, and a start stopped part way, always leave a wrong owner at that level.
Model: opus-5-5
bf047df6f4to08f8c25349