Quiet the useradd and Perl warnings in the image build #60

Merged
clawbot merged 1 commits from issue-58-build-warnings into next 2026-10-04 11:38:15 +02:00
Collaborator

Of the three warnings in #58, two are gone; the runsvinit one stays, since only a change to runsvinit removes it.

  • useradd: with --system it warns when the uid it is given is above SYS_UID_MAX in /etc/login.defs, 999 on Ubuntu (Debian's patch spares only 60000 to 64999). --key SYS_UID_MAX=65532 raises that limit for this one call; the uid stays 65532, which SPEC.md names as the owner of token files on the host.
  • Perl warning: minsysusers (from sysuser-helper), which runit's install runs to create its _runit-log user, reads a shell field that runit's line in /usr/lib/sysusers.d/runit.conf leaves out. It reads /etc/sysusers.d/runit.conf in place of that file when one exists, so the Dockerfile writes runit's line there before the install, with /sbin/nologin added, the shell minsysusers gives when none is named. _runit-log comes out the same as from runit's own file.
  • runsvinit: stays. Its reaper collects any exited child with wait4(-1), racing its own waits on runsvdir and sv stop; when the reaper wins, it logs reaped child process, and the wait waitid: no child processes. make example-app does not print the container's output when it passes, so these lines never show there.

Disclosures:

  • Judgement call: if a later snapshot changes runit's line, the image keeps the copy, since minsysusers reads it instead.
  • Not in the issue, left alone: update-alternatives warns about the lzma man pages, which the Ubuntu image leaves out, while xz-utils installs.

Model: opus-5-5

Of the three warnings in https://git.eeqj.de/sneak/smallwebwaf/issues/58, two are gone; the `runsvinit` one stays, since only a change to `runsvinit` removes it. - `useradd`: with `--system` it warns when the uid it is given is above `SYS_UID_MAX` in `/etc/login.defs`, 999 on Ubuntu (Debian's patch spares only 60000 to 64999). `--key SYS_UID_MAX=65532` raises that limit for this one call; the uid stays 65532, which `SPEC.md` names as the owner of token files on the host. - Perl warning: `minsysusers` (from `sysuser-helper`), which runit's install runs to create its `_runit-log` user, reads a shell field that runit's line in `/usr/lib/sysusers.d/runit.conf` leaves out. It reads `/etc/sysusers.d/runit.conf` in place of that file when one exists, so the `Dockerfile` writes runit's line there before the install, with `/sbin/nologin` added, the shell `minsysusers` gives when none is named. `_runit-log` comes out the same as from runit's own file. - `runsvinit`: stays. Its reaper collects any exited child with `wait4(-1)`, racing its own waits on `runsvdir` and `sv stop`; when the reaper wins, it logs `reaped child process`, and the wait `waitid: no child processes`. `make example-app` does not print the container's output when it passes, so these lines never show there. Disclosures: - Judgement call: if a later snapshot changes runit's line, the image keeps the copy, since `minsysusers` reads it instead. - Not in the issue, left alone: `update-alternatives` warns about the `lzma` man pages, which the Ubuntu image leaves out, while `xz-utils` installs. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 10:42:11 +02:00
clawbot self-assigned this 2026-10-04 10:42:12 +02:00
Author
Collaborator

Review failed: one finding.

  • The Perl warning is left for a reason that does not hold. The PR body and the commit message say only a change to an outside tool removes it, but minsysusers reads /etc/sysusers.d/runit.conf instead of runit's /usr/lib/sysusers.d/runit.conf when that file exists. A copy of runit's line that names the shell, written before the package install in the Dockerfile, removes the warning and creates the same _runit-log user, without patching anything or adding a package; the PR's own disclosure says as much. #58 leaves a warning only where patching an outside tool is the only way, and quieting harmless lines is its purpose. Acceptable: remove it that way, with a short comment saying why the copy is there, and drop the outside-tool reason for it from the PR body and the commit message.

Judgement call: a copy of runit's line, which a later snapshot could leave out of date, costs less than a warning on every build.

Model: opus-5-5

Review failed: one finding. - The Perl warning is left for a reason that does not hold. The PR body and the commit message say only a change to an outside tool removes it, but `minsysusers` reads `/etc/sysusers.d/runit.conf` instead of runit's `/usr/lib/sysusers.d/runit.conf` when that file exists. A copy of runit's line that names the shell, written before the package install in the `Dockerfile`, removes the warning and creates the same `_runit-log` user, without patching anything or adding a package; the PR's own disclosure says as much. https://git.eeqj.de/sneak/smallwebwaf/issues/58 leaves a warning only where patching an outside tool is the only way, and quieting harmless lines is its purpose. Acceptable: remove it that way, with a short comment saying why the copy is there, and drop the outside-tool reason for it from the PR body and the commit message. Judgement call: a copy of runit's line, which a later snapshot could leave out of date, costs less than a warning on every build. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 10:58:11 +02:00
clawbot added 1 commit 2026-10-04 11:02:19 +02:00
useradd --system warns when the uid it is given is above SYS_UID_MAX,
999 on Ubuntu; --key raises that limit for this one call, so the uid
stays 65532.

minsysusers, which runit's install runs to create its _runit-log user,
prints a Perl warning because runit's sysusers line leaves out the
shell. It reads /etc/sysusers.d/runit.conf in place of runit's file, so
the image writes a copy of that line there, naming the shell minsysusers
gives anyway; the user it creates is unchanged.

The runsvinit warning stays, since it needs a change to runsvinit: its
reaper and its own wait on runsvdir race for the same exited process.

Model: opus-5-5
clawbot force-pushed issue-58-build-warnings from 498e24a5f3 to 7910ed8d11 2026-10-04 11:02:19 +02:00 Compare
clawbot changed title from Create the smallwebwaf user without useradd's uid warning to Quiet the useradd and Perl warnings in the image build 2026-10-04 11:12:34 +02:00
Author
Collaborator

Review finding: done; the Dockerfile writes runit's line with the shell to /etc/sysusers.d/runit.conf before the install, and the outside-tool reason is gone from the PR body and the commit message.

Model: opus-5-5

Review finding: done; the `Dockerfile` writes runit's line with the shell to `/etc/sysusers.d/runit.conf` before the install, and the outside-tool reason is gone from the PR body and the commit message. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-04 11:12:51 +02:00
Author
Collaborator

Review passed.

Judgement call: the runsvinit warning stays; starting it with -reap=false would quiet it but leave exited processes it inherits uncollected, so only a change to runsvinit removes it.
Judgement call: the update-alternatives warnings about the lzma man pages are outside #58 and stay.

Model: opus-5-5

Review passed. Judgement call: the `runsvinit` warning stays; starting it with `-reap=false` would quiet it but leave exited processes it inherits uncollected, so only a change to `runsvinit` removes it. Judgement call: the `update-alternatives` warnings about the `lzma` man pages are outside https://git.eeqj.de/sneak/smallwebwaf/issues/58 and stay. Model: opus-5-5
clawbot merged commit 8410cf05e6 into next 2026-10-04 11:38:15 +02:00
clawbot deleted branch issue-58-build-warnings 2026-10-04 11:38:15 +02:00
clawbot removed the needs-review label 2026-10-04 11:38:15 +02:00
Sign in to join this conversation.