fix(firecracker): restore agent home ownership at boot
This commit is contained in:
@@ -271,6 +271,8 @@ class AgentProvider(ABC):
|
||||
# runtime, after every backend's copy/export path has completed.
|
||||
git_xdg_dir = f"{plan.guest_home}/.config/git"
|
||||
repair = bottle.exec(
|
||||
f"chown node:node {shlex.quote(plan.guest_home)} && "
|
||||
f"chmod 755 {shlex.quote(plan.guest_home)} && "
|
||||
f"mkdir -p {shlex.quote(git_xdg_dir)} && "
|
||||
f"chown -R node:node {shlex.quote(f'{plan.guest_home}/.config')} && "
|
||||
f"chmod -R u+rwX,go+rX {shlex.quote(f'{plan.guest_home}/.config')}",
|
||||
|
||||
@@ -373,6 +373,12 @@ mount -o remount,rw / 2>/dev/null
|
||||
# scratch dirs there — git worktrees, build temp, `git init /tmp/...`, etc.
|
||||
mkdir -p /tmp && chmod 1777 /tmp
|
||||
|
||||
# Rootfs export also maps the image's original owners to the unprivileged
|
||||
# host build uid. That uid is not guaranteed to be node's uid in the guest;
|
||||
# restore the home-directory boundary before any SSH provisioning runs.
|
||||
chown node:node /home/node 2>/dev/null || true
|
||||
chmod 755 /home/node 2>/dev/null || true
|
||||
|
||||
# Install the per-bottle SSH pubkey from the kernel cmdline.
|
||||
KEY=$(sed -n 's/.*bb_pubkey=\([^ ]*\).*/\1/p' /proc/cmdline | base64 -d 2>/dev/null)
|
||||
if [ -n "$KEY" ]; then
|
||||
|
||||
Reference in New Issue
Block a user