mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 12:39:42 +02:00
Two real bugs the review caught, both verified live against a real build on the Unraid host: 1. entrypoint.sh's chown fired on ANY ownership mismatch, not just a directory the daemon itself created root-owned. A host tree legitimately owned by some other account - an existing CODEMAN_CASES_PATH the README already allows pointing at a normal projects directory, or appdata under a different PUID/PGID convention than the one in use - got silently recursively re-owned with one log line to explain it. Now gated on the target actually being root-owned; anything else is a clean refusal naming the directory, its owner, and PUID/PGID. Start-Codeman.sh also now pre-creates CODEMAN_CASES_PATH the same way it already did CODEMAN_APPDATA_PATH, so Compose never has to materialise a missing bind source as root in the first place - the in-container chown becomes a safety net, not the primary mechanism. 2. The CLI-update chown (chown -R .../node_modules /usr/local/bin) handed the runtime account write access to entrypoint.sh itself (root-owned, executed as root on every container start with CHOWN/DAC_OVERRIDE/SETUID/SETGID) and the node binary - owning the DIRECTORY is enough to rename it aside and drop a replacement, which would let a compromised session arrange for its own script to run as root at the next restart. The four CLIs now install into a dedicated /opt/codeman-cli prefix (NPM_CONFIG_PREFIX); only that directory is chowned, /usr/local stays root-owned throughout. Smaller fixes from the same review: - Start-Codeman.sh's volume-refresh label filter wasn't project-scoped: a second Compose stack on the same host sharing the `codeman-dist` volume KEY could have had ITS volume deleted. Added a com.docker.compose.project filter, resolved from this stack's own `compose config --format json`. - Override-file precedence was backwards (checked .yaml before .yml; Compose actually prefers .yml) - swapped, plus a warning when both exist. - entrypoint.sh's setpriv now also passes --bounding-set -all, so CapBnd actually clears post-drop rather than just CapPrm/CapEff. - A comment on git_head_commit() noting it returns nothing for a worktree checkout (.git as a file), consistent with the script's existing -d .git convention elsewhere. - Doc drift: CLAUDE.md's Docker Compose section still described the old pre-created-and-chowned-by-hand model and didn't mention the root-then-drop entrypoint; the state-files list was missing docker-build-source.json; docs/docker-compose.md and docker/.env.example still had the pre-rename `Coding/codeman` path in one place each. Verified end to end against a real build on the Unraid host: a root-owned bind source is corrected as before; a directory owned by neither root nor PUID:PGID is refused rather than silently rewritten; a correctly-owned directory is left alone entirely; the four CLIs resolve via PATH from /opt/codeman-cli while /usr/local/bin, /usr/local/lib/node_modules and entrypoint.sh itself stay root-owned; CapBnd is fully cleared post-drop. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01R9ZSTEenc8soSu9bTi8Xru
77 lines
3.2 KiB
Bash
77 lines
3.2 KiB
Bash
# =============================================================================
|
|
# Codeman Docker Compose environment template
|
|
# Copy this file to .env and set the values for the Docker host.
|
|
# =============================================================================
|
|
|
|
TZ=Australia/Perth
|
|
|
|
# Optional overrides for direct `docker compose` use. The Bash start script
|
|
# detects these values from CODEMAN_APPDATA_PATH automatically. Compose uses
|
|
# 1000:1000 when the variables are omitted.
|
|
# PUID=1000
|
|
# PGID=1000
|
|
|
|
# Name of the account that runs Codeman and all local CLI sessions. Changing
|
|
# this value rebuilds the image with a matching account.
|
|
CODEMAN_RUNTIME_USER=codeman
|
|
|
|
# Required. Persistent Codeman application data, CLI credentials, and session
|
|
# state are stored here on the host and mounted at the runtime account's home
|
|
# directory in the container.
|
|
CODEMAN_APPDATA_PATH=/mnt/user/appdata/codeman
|
|
|
|
# Optional. Absolute host path of this Codeman checkout, mounted at
|
|
# /opt/codeman so App Settings -> Updates can update Codeman in place. The Bash
|
|
# start script detects it from the compose file's own location, so it only needs
|
|
# setting for direct `docker compose` use or a checkout kept elsewhere. Point it
|
|
# at a directory that is not a git checkout and in-app updates are unavailable.
|
|
# CODEMAN_REPO_PATH=/mnt/user/appdata/codeman/app
|
|
|
|
# Required for Docker cases. This must be an absolute path on the Docker host.
|
|
# Codeman and each isolated case use this same path, so it cannot be a
|
|
# container-only path such as /home/codeman/codeman-cases.
|
|
CODEMAN_CASES_PATH=/mnt/user/appdata/codeman/codeman-cases
|
|
|
|
# Required. Network bind address, host port, and local image tag.
|
|
CODEMAN_HOST=0.0.0.0
|
|
CODEMAN_PORT=3000
|
|
CODEMAN_IMAGE=codeman:local
|
|
|
|
# Required for any network-accessible Codeman instance. Use a unique, strong
|
|
# password. This file is safe to commit; copy it to .env and set the value.
|
|
CODEMAN_PASSWORD=changeme
|
|
|
|
# Required. Username for Codeman HTTP Basic authentication.
|
|
CODEMAN_USERNAME=admin
|
|
|
|
# Optional: authenticate Gemini CLI without an interactive login.
|
|
GEMINI_API_KEY=
|
|
|
|
# Linux default. On Docker Desktop, use the socket path supported by your
|
|
# Docker installation when it differs from /var/run/docker.sock.
|
|
DOCKER_SOCKET=/var/run/docker.sock
|
|
|
|
# Optional override for direct `docker compose` use. The Bash start script
|
|
# detects this from DOCKER_SOCKET automatically. The direct Compose default is
|
|
# 999, but the correct value depends on the Docker host.
|
|
# DOCKER_SOCKET_GID=999
|
|
|
|
# Set to 1 only when Docker-case hook callbacks are required.
|
|
CODEMAN_DOCKER_BRIDGE_HOOKS=0
|
|
|
|
# Set to 1 when `docker info` reports `SwapLimit=false`. The case memory limit
|
|
# remains active; Codeman omits --memory-swap and filters the daemon's exact
|
|
# unsupported-swap warning while preserving all other Docker create errors.
|
|
CODEMAN_DOCKER_DISABLE_SWAP_LIMIT=0
|
|
|
|
# Required only when applying the macvlan example in README.md.
|
|
CODEMAN_MACVLAN_NETWORK=br0.11
|
|
CODEMAN_IPV4_ADDRESS=10.10.11.236
|
|
CODEMAN_MAC_ADDRESS=02:10:11:00:00:EC
|
|
|
|
# Required only when creating a new managed macvlan network, rather than using
|
|
# the external-network macvlan example.
|
|
CODEMAN_MACVLAN_PARENT=br0.11
|
|
CODEMAN_MACVLAN_SUBNET=10.10.11.0/24
|
|
CODEMAN_MACVLAN_GATEWAY=10.10.11.1
|