fix(docker): merge-time fixes for #490

- test: every ENV PATH= line in server.Dockerfile must start $PATH:, and
  the ~/.local/bin append is pinned alongside /opt/codeman-cli/bin
- invariants + CLAUDE.md: the append-only PATH rule names ~/.local/bin too
- docker-compose.md: Settings-installed CLIs live in ~/.local on the
  app-data mount; reinstall once after upgrading; hand-run npm installs
  need --prefix ~/.local
- installEnv() JSDoc describes the in-container npm prefix redirect

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Codeman maintainer
2026-09-28 16:28:29 +02:00
parent 83e39c40a1
commit 627b76739c
5 changed files with 10 additions and 7 deletions
+3 -4
View File
@@ -110,15 +110,14 @@ describe('docker-compose.yaml cap_add covers what entrypoint.sh and init:true ne
});
describe('the runtime-owned CLI prefix never shadows root commands', () => {
it('server.Dockerfile appends /opt/codeman-cli/bin to PATH rather than prepending it', () => {
it('server.Dockerfile appends the runtime-writable CLI dirs to PATH rather than prepending them', () => {
const pathLines = dockerfile.split('\n').filter((l) => /^ENV PATH=/.test(l));
expect(pathLines.length).toBeGreaterThan(0);
for (const line of pathLines) {
expect(line, 'a writable prefix ahead of $PATH lets a planted setpriv run as root').not.toMatch(
/^ENV PATH=\/opt\/codeman-cli/
);
expect(line, 'a writable prefix ahead of $PATH lets a planted setpriv run as root').toMatch(/^ENV PATH=\$PATH:/);
}
expect(pathLines).toContain('ENV PATH=$PATH:/opt/codeman-cli/bin');
expect(pathLines).toContain('ENV PATH=$PATH:/home/${CODEMAN_RUNTIME_USER}/.local/bin');
});
it('entrypoint.sh pins PATH to the system directories before its first command', () => {