From 08f8c2534965a3c006c8daaca9b37c081e764317 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Tue, 29 Sep 2026 09:24:54 +0000 Subject: [PATCH] Container makes /var/lib/pixa usable before starting pixad (closes #159) The entrypoint now creates /var/lib/pixa if it is missing. When the directory or one of its top-level entries belongs to another user or group, it gives the whole tree to pixad (uid and gid 65532); it then sets the directory's mode to 750 and runs the server as pixad as before. Data left by a run under another uid is taken over this way. Only the top level is checked, so a normal start does not walk the cache; the tree is changed deepest first, so an interrupted start is finished by the next one. "Running under upaas" in README.md no longer tells the operator to create or chown the host directory. Model: opus-5-5 --- README.md | 9 ++------- TODO.md | 7 +++++++ deploy/docker-entrypoint.sh | 18 +++++++++++++----- 3 files changed, 22 insertions(+), 12 deletions(-) diff --git a/README.md b/README.md index 9321291..ed5b3b0 100644 --- a/README.md +++ b/README.md @@ -40,9 +40,8 @@ What the [upaas](https://git.eeqj.de/sneak/upaas) app for pixa needs: - **Port:** pixa listens on container port `8080`. - **Volume:** container path `/var/lib/pixa`, where pixa keeps its - database and cache. upaas bind-mounts the host path it is given and - does not create it, so the host directory must exist before the first - deploy. + database and cache. Creating the host directory when it is missing is + upaas's job, tracked in https://git.eeqj.de/sneak/upaas/issues/235. - **Environment variables:** - `PIXA_SIGNING_KEY` (required): secret for signed and encrypted URLs and login, 32+ characters, for example from @@ -58,10 +57,6 @@ What the [upaas](https://git.eeqj.de/sneak/upaas) app for pixa needs: `healthy`. The probe uses the port from `PORT` (default `8080`), so a port changed only in a mounted config file is not seen by it: change the port with `PORT`. -- **First run:** create the host directory, owned by root or by uid - `65532` and gid `65532`. The server runs as the container's `pixad` - user, which has that uid and gid, and the container gives the - directory to `pixad` when it starts. ## Rationale diff --git a/TODO.md b/TODO.md index bb548f5..637e3a5 100644 --- a/TODO.md +++ b/TODO.md @@ -29,6 +29,13 @@ P2: security: referer blacklist # Completed Steps +- 2026-09-29 the container makes `/var/lib/pixa` usable by itself (closes + #159): `deploy/docker-entrypoint.sh` creates the directory if it is missing, + gives the directory and everything in it to `pixad` when the directory or one + of its top-level entries belongs to another user or group, sets its mode to + `750`, then runs the server as `pixad`; data left by an earlier run under + another uid is taken over this way; "Running under upaas" in `README.md` no + longer tells the operator to create or chown the host directory. - 2026-09-29 variant content types kept in memory (closes #70): `Cache.metaCache` holds the content types of up to 10,000 variants in an LRU (`github.com/hashicorp/golang-lru/v2`), filled by `StoreVariant` and by diff --git a/deploy/docker-entrypoint.sh b/deploy/docker-entrypoint.sh index 691ff2f..abb3f16 100755 --- a/deploy/docker-entrypoint.sh +++ b/deploy/docker-entrypoint.sh @@ -1,14 +1,22 @@ #!/bin/sh # deploy/docker-entrypoint.sh: the Docker image's ENTRYPOINT. It runs as -# root only to give /var/lib/pixa to pixad: a host directory -# bind-mounted there keeps its host owner, often root, and pixad could -# not write to it. The server itself always runs as pixad. +# root only to make /var/lib/pixa usable by pixad: a host directory +# bind-mounted there keeps its host owner, often root, and data from an +# earlier run may belong to another uid. The server itself always runs +# as pixad. set -eu main() { - if [ "$(stat -c %U /var/lib/pixa)" != pixad ]; then - chown pixad:pixad /var/lib/pixa + mkdir -p /var/lib/pixa + # Only the directory and its top-level entries are checked, so a + # normal start does not walk the cache. -depth gives each directory + # to pixad after its contents, so a start stopped part way leaves + # something at the top for the next start to find; -h changes a + # symlink itself, never the file it points to. + if [ -n "$(find /var/lib/pixa -maxdepth 1 \( ! -user pixad -o ! -group pixad \))" ]; then + find /var/lib/pixa -depth -exec chown -h pixad:pixad {} + fi + chmod 750 /var/lib/pixa exec su-exec pixad /usr/local/bin/pixad "$@" } -- 2.54.0