From 7910ed8d11e3cb52d804fbce9e0c75c3ab63c4e6 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Sun, 4 Oct 2026 08:41:54 +0000 Subject: [PATCH] Quiet the useradd and Perl warnings in the image build (closes #58) useradd --system warns when the uid it is given is above SYS_UID_MAX, 999 on Ubuntu; --key raises that limit for this one call, so the uid stays 65532. minsysusers, which runit's install runs to create its _runit-log user, prints a Perl warning because runit's sysusers line leaves out the shell. It reads /etc/sysusers.d/runit.conf in place of runit's file, so the image writes a copy of that line there, naming the shell minsysusers gives anyway; the user it creates is unchanged. The runsvinit warning stays, since it needs a change to runsvinit: its reaper and its own wait on runsvdir race for the same exited process. Model: opus-5-5 --- Dockerfile | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 30aace9..5c52dfb 100644 --- a/Dockerfile +++ b/Dockerfile @@ -79,6 +79,15 @@ RUN git checkout --quiet --detach b4b2c785308b1ce785b6155c7fe5f16879080193 \ # ubuntu 26.04, 2026-09-27 FROM ubuntu@sha256:f144425ff09be612d6d9ad965196e9cdc23dae1f42110a8a11a3e9a8198759f7 +# runit's install creates its _runit-log user with minsysusers, which +# reads this file in place of runit's /usr/lib/sysusers.d/runit.conf. +# runit's line leaves out the shell, and minsysusers prints a Perl +# warning for that; this copy of it names /sbin/nologin, the shell +# minsysusers gives when none is named. +RUN mkdir /etc/sysusers.d \ + && echo 'u _runit-log - "runit svlogd user" /nonexistent /sbin/nologin' \ + > /etc/sysusers.d/runit.conf + # ca-certificates, nix-bin and runit, from Ubuntu's archive as it was at # the snapshot moment, which is never earlier than the Ubuntu image above. # apt checks every package against the snapshot's InRelease files, and @@ -130,9 +139,12 @@ ENV PATH=${PATH}:/nix/var/nix/profiles/default/bin COPY --from=runsvinit /usr/local/bin/runsvinit /usr/local/bin/runsvinit COPY --from=builder /usr/local/bin/smallwebwaf /usr/local/bin/smallwebwaf +# 65532 is above the uids Ubuntu keeps for system users, which end at +# 999; useradd warns about it unless --key raises that end for this call. RUN groupadd --system --gid 65532 smallwebwaf \ - && useradd --system --uid 65532 --gid smallwebwaf --no-create-home \ - --shell /usr/sbin/nologin smallwebwaf + && useradd --system --key SYS_UID_MAX=65532 --uid 65532 \ + --gid smallwebwaf --no-create-home --shell /usr/sbin/nologin \ + smallwebwaf # runsvinit starts runit's runsvdir on /etc/service, where Ubuntu's sv # looks too. -- 2.54.0