fix(firecracker): restore agent home ownership at boot
test / integration-docker (pull_request) Successful in 20s
tracker-policy-pr / check-pr (pull_request) Successful in 20s
test / unit (pull_request) Successful in 40s
lint / lint (push) Successful in 55s
test / integration-firecracker (pull_request) Successful in 4m29s
test / coverage (pull_request) Failing after 16s
test / publish-infra (pull_request) Has been skipped
test / integration-docker (pull_request) Successful in 20s
tracker-policy-pr / check-pr (pull_request) Successful in 20s
test / unit (pull_request) Successful in 40s
lint / lint (push) Successful in 55s
test / integration-firecracker (pull_request) Successful in 4m29s
test / coverage (pull_request) Failing after 16s
test / publish-infra (pull_request) Has been skipped
This commit is contained in:
@@ -373,6 +373,12 @@ mount -o remount,rw / 2>/dev/null
|
||||
# scratch dirs there — git worktrees, build temp, `git init /tmp/...`, etc.
|
||||
mkdir -p /tmp && chmod 1777 /tmp
|
||||
|
||||
# Rootfs export also maps the image's original owners to the unprivileged
|
||||
# host build uid. That uid is not guaranteed to be node's uid in the guest;
|
||||
# restore the home-directory boundary before any SSH provisioning runs.
|
||||
chown node:node /home/node 2>/dev/null || true
|
||||
chmod 755 /home/node 2>/dev/null || true
|
||||
|
||||
# Install the per-bottle SSH pubkey from the kernel cmdline.
|
||||
KEY=$(sed -n 's/.*bb_pubkey=\([^ ]*\).*/\1/p' /proc/cmdline | base64 -d 2>/dev/null)
|
||||
if [ -n "$KEY" ]; then
|
||||
|
||||
Reference in New Issue
Block a user