sneak's rule in #42: the container makes its data directory usable itself, with no step on the host.
entrypoint.sh creates /var/lib/berlin.sneak.app.routewatch if it is missing and stops the start when any step fails. Before, with no set -e, a failed cd went on to change the ownership of whatever directory the script was in, and a failed chown still started the daemon. Taking ownership of the directory (chown -R, chmod 700) and switching to the routewatch user through setpriv were already there and are unchanged.
README.md, "Running under upaas": the volume line now says only which container path to mount.
TODO.md: Completed Steps line.
The data path and the uid are unchanged.
Disclosures:
Judgement call: set -euo pipefail, as the repo's code style guide asks of scripts, where the plan said set -e.
Deviation: the runs the issue asks for (an empty root-owned directory, a directory holding another uid's data, and a second start of each) were done by hand on the image from make docker, with bind mounts the way upaas mounts them; not under upaas itself, and not added as an automated test.
A bind-mounted directory cannot be missing (Docker refuses a missing source), so the created-if-missing case was checked with /var/lib hidden under an empty tmpfs.
Model: opus-5-5
sneak's rule in https://git.eeqj.de/sneak/routewatch/issues/42: the container makes its data directory usable itself, with no step on the host.
- `entrypoint.sh` creates `/var/lib/berlin.sneak.app.routewatch` if it is missing and stops the start when any step fails. Before, with no `set -e`, a failed `cd` went on to change the ownership of whatever directory the script was in, and a failed `chown` still started the daemon. Taking ownership of the directory (`chown -R`, `chmod 700`) and switching to the `routewatch` user through `setpriv` were already there and are unchanged.
- `README.md`, "Running under upaas": the volume line now says only which container path to mount.
- `TODO.md`: Completed Steps line.
The data path and the uid are unchanged.
Disclosures:
- Judgement call: `set -euo pipefail`, as the repo's code style guide asks of scripts, where the plan said `set -e`.
- Deviation: the runs the issue asks for (an empty root-owned directory, a directory holding another uid's data, and a second start of each) were done by hand on the image from `make docker`, with bind mounts the way upaas mounts them; not under upaas itself, and not added as an automated test.
- A bind-mounted directory cannot be missing (Docker refuses a missing source), so the created-if-missing case was checked with `/var/lib` hidden under an empty tmpfs.
Model: opus-5-5
The entrypoint now creates the data directory if it is missing and stops
the start when any step fails, so a failed cd can no longer change the
ownership of some other directory. It already took ownership of the
directory and dropped to the routewatch user; that is unchanged. The
README's upaas section now says only which path to mount.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
sneak's rule in #42: the container makes its data directory usable itself, with no step on the host.
entrypoint.shcreates/var/lib/berlin.sneak.app.routewatchif it is missing and stops the start when any step fails. Before, with noset -e, a failedcdwent on to change the ownership of whatever directory the script was in, and a failedchownstill started the daemon. Taking ownership of the directory (chown -R,chmod 700) and switching to theroutewatchuser throughsetprivwere already there and are unchanged.README.md, "Running under upaas": the volume line now says only which container path to mount.TODO.md: Completed Steps line.The data path and the uid are unchanged.
Disclosures:
set -euo pipefail, as the repo's code style guide asks of scripts, where the plan saidset -e.make docker, with bind mounts the way upaas mounts them; not under upaas itself, and not added as an automated test./var/libhidden under an empty tmpfs.Model: opus-5-5
Review passed.
Model: opus-5-5