fix(agent-images): own Git config directory
This commit is contained in:
@@ -47,6 +47,11 @@ RUN apt-get update \
|
|||||||
RUN npm install -g --no-fund --no-audit @anthropic-ai/claude-code@2.1.172 \
|
RUN npm install -g --no-fund --no-audit @anthropic-ai/claude-code@2.1.172 \
|
||||||
&& npm cache clean --force
|
&& npm cache clean --force
|
||||||
|
|
||||||
|
# Git reads both ~/.gitconfig and ~/.config/git/config. Keep its XDG config
|
||||||
|
# path traversable by the non-root runtime user so permission errors do not
|
||||||
|
# suppress bot-bottle's git-gate insteadOf rules.
|
||||||
|
RUN install -d -o node -g node -m 755 /home/node/.config /home/node/.config/git
|
||||||
|
|
||||||
# Run as a non-root user. The node image already provides a `node` user
|
# Run as a non-root user. The node image already provides a `node` user
|
||||||
# (uid 1000) with a home directory, which is where claude-code will write
|
# (uid 1000) with a home directory, which is where claude-code will write
|
||||||
# its session state.
|
# its session state.
|
||||||
|
|||||||
@@ -24,6 +24,8 @@ RUN apt-get update \
|
|||||||
&& apt-get install -y --no-install-recommends python3 python3-pip python3-venv \
|
&& apt-get install -y --no-install-recommends python3 python3-pip python3-venv \
|
||||||
&& rm -rf /var/lib/apt/lists/*
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
RUN install -d -o node -g node -m 755 /home/node/.config /home/node/.config/git
|
||||||
|
|
||||||
USER node
|
USER node
|
||||||
WORKDIR /home/node
|
WORKDIR /home/node
|
||||||
|
|
||||||
|
|||||||
@@ -23,7 +23,8 @@ RUN apt-get update \
|
|||||||
RUN npm install -g --ignore-scripts --no-fund --no-audit @earendil-works/pi-coding-agent \
|
RUN npm install -g --ignore-scripts --no-fund --no-audit @earendil-works/pi-coding-agent \
|
||||||
&& npm cache clean --force
|
&& npm cache clean --force
|
||||||
|
|
||||||
RUN mkdir -p /home/node/.pi/agent \
|
RUN install -d -o node -g node -m 755 /home/node/.config /home/node/.config/git \
|
||||||
|
&& mkdir -p /home/node/.pi/agent \
|
||||||
/home/node/.pi/context-mode/sessions \
|
/home/node/.pi/context-mode/sessions \
|
||||||
/tmp/pi-subagents-uid-1000 \
|
/tmp/pi-subagents-uid-1000 \
|
||||||
&& chown -R node:node /home/node/.pi /tmp \
|
&& chown -R node:node /home/node/.pi /tmp \
|
||||||
|
|||||||
@@ -25,6 +25,9 @@ modify the bottle or cannot run at all.
|
|||||||
`node:22-trixie-slim`, based on Debian 13 (the current stable release).
|
`node:22-trixie-slim`, based on Debian 13 (the current stable release).
|
||||||
- Every built-in agent image installs Podman from Debian stable.
|
- Every built-in agent image installs Podman from Debian stable.
|
||||||
- Every built-in agent image retains an SSH client for Git-over-SSH workflows.
|
- Every built-in agent image retains an SSH client for Git-over-SSH workflows.
|
||||||
|
- The non-root agent user owns a traversable XDG Git configuration directory,
|
||||||
|
so Git can load bot-bottle's global git-gate rewrites without permission
|
||||||
|
errors.
|
||||||
- A shared test enforces both requirements for current and future built-in
|
- A shared test enforces both requirements for current and future built-in
|
||||||
providers.
|
providers.
|
||||||
|
|
||||||
|
|||||||
@@ -37,6 +37,13 @@ class TestBuiltinAgentImages(unittest.TestCase):
|
|||||||
re.compile(r"(?m)^\s*openssh-client(?:\s|\\|$)"),
|
re.compile(r"(?m)^\s*openssh-client(?:\s|\\|$)"),
|
||||||
)
|
)
|
||||||
|
|
||||||
|
def test_all_prepare_node_git_config_directory(self):
|
||||||
|
for dockerfile in _AGENT_DOCKERFILES:
|
||||||
|
with self.subTest(provider=dockerfile.parent.name):
|
||||||
|
dockerfile_text = dockerfile.read_text()
|
||||||
|
self.assertIn("install -d -o node -g node", dockerfile_text)
|
||||||
|
self.assertIn("/home/node/.config/git", dockerfile_text)
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
if __name__ == "__main__":
|
||||||
unittest.main()
|
unittest.main()
|
||||||
|
|||||||
Reference in New Issue
Block a user