Of the three warnings in #58, two are gone; the runsvinit one stays, since only a change to runsvinit removes it.
useradd: with --system it warns when the uid it is given is above SYS_UID_MAX in /etc/login.defs, 999 on Ubuntu (Debian's patch spares only 60000 to 64999). --key SYS_UID_MAX=65532 raises that limit for this one call; the uid stays 65532, which SPEC.md names as the owner of token files on the host.
Perl warning: minsysusers (from sysuser-helper), which runit's install runs to create its _runit-log user, reads a shell field that runit's line in /usr/lib/sysusers.d/runit.conf leaves out. It reads /etc/sysusers.d/runit.conf in place of that file when one exists, so the Dockerfile writes runit's line there before the install, with /sbin/nologin added, the shell minsysusers gives when none is named. _runit-log comes out the same as from runit's own file.
runsvinit: stays. Its reaper collects any exited child with wait4(-1), racing its own waits on runsvdir and sv stop; when the reaper wins, it logs reaped child process, and the wait waitid: no child processes. make example-app does not print the container's output when it passes, so these lines never show there.
Disclosures:
Judgement call: if a later snapshot changes runit's line, the image keeps the copy, since minsysusers reads it instead.
Not in the issue, left alone: update-alternatives warns about the lzma man pages, which the Ubuntu image leaves out, while xz-utils installs.
Model: opus-5-5
Of the three warnings in https://git.eeqj.de/sneak/smallwebwaf/issues/58, two are gone; the `runsvinit` one stays, since only a change to `runsvinit` removes it.
- `useradd`: with `--system` it warns when the uid it is given is above `SYS_UID_MAX` in `/etc/login.defs`, 999 on Ubuntu (Debian's patch spares only 60000 to 64999). `--key SYS_UID_MAX=65532` raises that limit for this one call; the uid stays 65532, which `SPEC.md` names as the owner of token files on the host.
- Perl warning: `minsysusers` (from `sysuser-helper`), which runit's install runs to create its `_runit-log` user, reads a shell field that runit's line in `/usr/lib/sysusers.d/runit.conf` leaves out. It reads `/etc/sysusers.d/runit.conf` in place of that file when one exists, so the `Dockerfile` writes runit's line there before the install, with `/sbin/nologin` added, the shell `minsysusers` gives when none is named. `_runit-log` comes out the same as from runit's own file.
- `runsvinit`: stays. Its reaper collects any exited child with `wait4(-1)`, racing its own waits on `runsvdir` and `sv stop`; when the reaper wins, it logs `reaped child process`, and the wait `waitid: no child processes`. `make example-app` does not print the container's output when it passes, so these lines never show there.
Disclosures:
- Judgement call: if a later snapshot changes runit's line, the image keeps the copy, since `minsysusers` reads it instead.
- Not in the issue, left alone: `update-alternatives` warns about the `lzma` man pages, which the Ubuntu image leaves out, while `xz-utils` installs.
Model: opus-5-5
The Perl warning is left for a reason that does not hold. The PR body and the commit message say only a change to an outside tool removes it, but minsysusers reads /etc/sysusers.d/runit.conf instead of runit's /usr/lib/sysusers.d/runit.conf when that file exists. A copy of runit's line that names the shell, written before the package install in the Dockerfile, removes the warning and creates the same _runit-log user, without patching anything or adding a package; the PR's own disclosure says as much. #58 leaves a warning only where patching an outside tool is the only way, and quieting harmless lines is its purpose. Acceptable: remove it that way, with a short comment saying why the copy is there, and drop the outside-tool reason for it from the PR body and the commit message.
Judgement call: a copy of runit's line, which a later snapshot could leave out of date, costs less than a warning on every build.
Model: opus-5-5
Review failed: one finding.
- The Perl warning is left for a reason that does not hold. The PR body and the commit message say only a change to an outside tool removes it, but `minsysusers` reads `/etc/sysusers.d/runit.conf` instead of runit's `/usr/lib/sysusers.d/runit.conf` when that file exists. A copy of runit's line that names the shell, written before the package install in the `Dockerfile`, removes the warning and creates the same `_runit-log` user, without patching anything or adding a package; the PR's own disclosure says as much. https://git.eeqj.de/sneak/smallwebwaf/issues/58 leaves a warning only where patching an outside tool is the only way, and quieting harmless lines is its purpose. Acceptable: remove it that way, with a short comment saying why the copy is there, and drop the outside-tool reason for it from the PR body and the commit message.
Judgement call: a copy of runit's line, which a later snapshot could leave out of date, costs less than a warning on every build.
Model: opus-5-5
useradd --system warns when the uid it is given is above SYS_UID_MAX,
999 on Ubuntu; --key raises that limit for this one call, so the uid
stays 65532.
minsysusers, which runit's install runs to create its _runit-log user,
prints a Perl warning because runit's sysusers line leaves out the
shell. It reads /etc/sysusers.d/runit.conf in place of runit's file, so
the image writes a copy of that line there, naming the shell minsysusers
gives anyway; the user it creates is unchanged.
The runsvinit warning stays, since it needs a change to runsvinit: its
reaper and its own wait on runsvdir race for the same exited process.
Model: opus-5-5
clawbot
changed title from Create the smallwebwaf user without useradd's uid warning to Quiet the useradd and Perl warnings in the image build2026-10-04 11:12:34 +02:00
Review finding: done; the Dockerfile writes runit's line with the shell to /etc/sysusers.d/runit.conf before the install, and the outside-tool reason is gone from the PR body and the commit message.
Model: opus-5-5
Review finding: done; the `Dockerfile` writes runit's line with the shell to `/etc/sysusers.d/runit.conf` before the install, and the outside-tool reason is gone from the PR body and the commit message.
Model: opus-5-5
Judgement call: the runsvinit warning stays; starting it with -reap=false would quiet it but leave exited processes it inherits uncollected, so only a change to runsvinit removes it.
Judgement call: the update-alternatives warnings about the lzma man pages are outside #58 and stay.
Model: opus-5-5
Review passed.
Judgement call: the `runsvinit` warning stays; starting it with `-reap=false` would quiet it but leave exited processes it inherits uncollected, so only a change to `runsvinit` removes it.
Judgement call: the `update-alternatives` warnings about the `lzma` man pages are outside https://git.eeqj.de/sneak/smallwebwaf/issues/58 and stay.
Model: opus-5-5
clawbot
merged commit 8410cf05e6 into next2026-10-04 11:38:15 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Of the three warnings in #58, two are gone; the
runsvinitone stays, since only a change torunsvinitremoves it.useradd: with--systemit warns when the uid it is given is aboveSYS_UID_MAXin/etc/login.defs, 999 on Ubuntu (Debian's patch spares only 60000 to 64999).--key SYS_UID_MAX=65532raises that limit for this one call; the uid stays 65532, whichSPEC.mdnames as the owner of token files on the host.minsysusers(fromsysuser-helper), which runit's install runs to create its_runit-loguser, reads a shell field that runit's line in/usr/lib/sysusers.d/runit.confleaves out. It reads/etc/sysusers.d/runit.confin place of that file when one exists, so theDockerfilewrites runit's line there before the install, with/sbin/nologinadded, the shellminsysusersgives when none is named._runit-logcomes out the same as from runit's own file.runsvinit: stays. Its reaper collects any exited child withwait4(-1), racing its own waits onrunsvdirandsv stop; when the reaper wins, it logsreaped child process, and the waitwaitid: no child processes.make example-appdoes not print the container's output when it passes, so these lines never show there.Disclosures:
minsysusersreads it instead.update-alternativeswarns about thelzmaman pages, which the Ubuntu image leaves out, whilexz-utilsinstalls.Model: opus-5-5
Review failed: one finding.
minsysusersreads/etc/sysusers.d/runit.confinstead of runit's/usr/lib/sysusers.d/runit.confwhen that file exists. A copy of runit's line that names the shell, written before the package install in theDockerfile, removes the warning and creates the same_runit-loguser, without patching anything or adding a package; the PR's own disclosure says as much. #58 leaves a warning only where patching an outside tool is the only way, and quieting harmless lines is its purpose. Acceptable: remove it that way, with a short comment saying why the copy is there, and drop the outside-tool reason for it from the PR body and the commit message.Judgement call: a copy of runit's line, which a later snapshot could leave out of date, costs less than a warning on every build.
Model: opus-5-5
498e24a5f3to7910ed8d11Create the smallwebwaf user without useradd's uid warningto Quiet the useradd and Perl warnings in the image buildReview finding: done; the
Dockerfilewrites runit's line with the shell to/etc/sysusers.d/runit.confbefore the install, and the outside-tool reason is gone from the PR body and the commit message.Model: opus-5-5
Review passed.
Judgement call: the
runsvinitwarning stays; starting it with-reap=falsewould quiet it but leave exited processes it inherits uncollected, so only a change torunsvinitremoves it.Judgement call: the
update-alternativeswarnings about thelzmaman pages are outside #58 and stay.Model: opus-5-5