Skip to content

Fix startup with host IDs of system accounts, php without sudo and PHP startup warnings - #416

Merged
mistraloz merged 4 commits into
thecodingmachine:v5from
mistraloz:fix/startup-user-and-proxy
Oct 9, 2026
Merged

mistraloz merged 4 commits into
thecodingmachine:v5from
mistraloz:fix/startup-user-and-proxy

Conversation

@mistraloz

@mistraloz mistraloz commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

This PR fixes :

  • Bug
  • Feature
  • Breaking changes
  1. User ID conflict / permission issues with GitLab Runner in v5 #408: host IDs used by a system account of the image. The commands are run by the owner of the working
    directory. On Ubuntu 24.04, IDs such as 998 belong to system accounts of the image (systemd-network), and are
    also the ID of the gitlab-runner user on many CI hosts: the commands were run with this account, which has no
    home directory and no sudo (touch ~/.startup_done: Permission denied). Setting DOCKER_USER=998 failed too
    (usermod: UID '998' already exists). The system account is now moved to a free ID, so that the docker user
    takes the host ID. Its ID is changed in /etc/passwd: usermod would also change the owner of the files of its
    home directory (/, including the mounted volume). Nothing changes for 0, 33 (www-data), 65534 and the
    IDs that are not used in the image.
  2. Suggestion: check if the user can run sudo in PHP proxy #253: sudo -u www-data php ... printed a sudo password error on each call, and failed with
    Unexpected PHP proxy output when a PHP_* variable had changed. The proxy now runs PHP with the current
    configuration when sudo is not available.
  3. PHP startup warnings stopping the container. A PHP warning (e.g. an extension that cannot be loaded) was
    written in the output of the scripts generating the startup configuration: syntax error in generated_conf.ini,
    supercronic exiting on a bad crontab line, bash syntax errors in the startup commands. These scripts now send
    PHP errors to stderr: the warnings are only logged.

Fixes #408
Fixes #253

Test plan (required)

New tests: test_defaultUserTakesUidOfSystemAccount and test_userWithoutSudoCanRunPhp (users-rights.sh),
test_phpStartupWarning (tool-startup-command.sh). A test that had the same name as another one (only the last one was run) is renamed test_defaultUserCanBeAnExistingUser.

Checklist

  • I followed the guidelines in CONTRIBUTING guide
  • I have squashed any insignificant commits
  • This change has comments for package types, values, functions, and non-obvious lines of code

…guration

The output of these scripts is written to generated_conf.ini and to the crontab,
or run by bash. A PHP warning (e.g. an extension that cannot be loaded) was
written in this output: syntax error in generated_conf.ini, supercronic exiting
on a "bad crontab line" and bash syntax errors stopping the container. The
warnings are now only logged.
…use sudo

"sudo -u www-data php ..." printed a sudo password error on each call, and
failed with "Unexpected PHP proxy output" when a PHP_* variable had changed
(the cache file is not writable by www-data). The proxy now runs PHP with the
current configuration when sudo is not available.

Fixes thecodingmachine#253
… account has it

The user running the commands is the owner of the working directory. When its ID
belongs to a system account of the image (e.g. 998 is systemd-network in Ubuntu
24.04, and the ID of the gitlab-runner user on many hosts), the commands were run
with this account: no home directory, no sudo ("touch ~/.startup_done:
Permission denied"). Setting DOCKER_USER to such an ID failed ("usermod: UID
'998' already exists").

The system account is now moved to a free ID, so that the docker user takes the
ID of the host user. Its ID is changed in /etc/passwd: usermod would also change
the owner of the files of its home directory ("/").

Also rename a test that had the same name as another one (only the last one was run).

Fixes thecodingmachine#408
@mistraloz mistraloz added the bug Something isn't working label Oct 9, 2026
@mistraloz
mistraloz merged commit 22c0833 into thecodingmachine:v5 Oct 9, 2026
25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

User ID conflict / permission issues with GitLab Runner in v5 Suggestion: check if the user can run sudo in PHP proxy

1 participant