Skip to content

Commit 1319004

Browse files
committed
Dockerfile: fix ownership — USER root before chown, switch back to lpb
COPY creates files as root. chown as non-root user fails. Now: USER root → chown → USER lpb for all root-owned dirs.
1 parent 31cb863 commit 1319004

1 file changed

Lines changed: 6 additions & 3 deletions

File tree

‎Dockerfile‎

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -155,15 +155,18 @@ COPY --chmod=755 support/entrypoint-cli.sh /opt/devstack/entrypoint-cli.sh
155155
RUN mkdir -p /home/lpb/.local/bin
156156
COPY --chmod=755 support/lpb-config /home/lpb/.local/bin/lpb-config
157157

158-
RUN mkdir -p /home/lpb/.agent-browser/sessions && chown -R 1000:1000 /home/lpb/.agent-browser
158+
# ─── Ownership (must run as root — COPY creates files as root) ───────────
159+
USER root
160+
RUN chown -R 1000:1000 /home/lpb /opt/devstack /opt/pi-support /home/lpb/.agent-browser
161+
USER lpb
159162

160163
# ─── Git credential helper ────────────────────────────────────────────
161164
# Points git to gh auth for GitHub HTTPS operations. No sensitive data
162165
# baked in — the actual token is resolved at runtime from
163166
# /home/lpb/.config/gh/hosts.yml (volume-mounted from host).
167+
USER root
164168
RUN printf '[credential "https://github.com"]\n helper = !gh auth git-credential\n[credential "https://gist.github.com"]\n helper = !gh auth git-credential\n' > /home/lpb/.gitconfig && chown 1000:1000 /home/lpb/.gitconfig
165-
166-
RUN chown -R 1000:1000 /home/lpb
169+
USER lpb
167170

168171
# ─── Shell PATH (npm global bin, local bin) ──────────────────────────
169172
# Ensures agent-browser, pi, and other npm-global tools are on PATH

0 commit comments

Comments
 (0)