Repository navigation
Fix startup with host IDs of system accounts, php without sudo and PHP startup warnings - #416
Merged
mistraloz merged 4 commits intoOct 9, 2026
Conversation
…guration The output of these scripts is written to generated_conf.ini and to the crontab, or run by bash. A PHP warning (e.g. an extension that cannot be loaded) was written in this output: syntax error in generated_conf.ini, supercronic exiting on a "bad crontab line" and bash syntax errors stopping the container. The warnings are now only logged.
…use sudo "sudo -u www-data php ..." printed a sudo password error on each call, and failed with "Unexpected PHP proxy output" when a PHP_* variable had changed (the cache file is not writable by www-data). The proxy now runs PHP with the current configuration when sudo is not available. Fixes thecodingmachine#253
… account has it
The user running the commands is the owner of the working directory. When its ID
belongs to a system account of the image (e.g. 998 is systemd-network in Ubuntu
24.04, and the ID of the gitlab-runner user on many hosts), the commands were run
with this account: no home directory, no sudo ("touch ~/.startup_done:
Permission denied"). Setting DOCKER_USER to such an ID failed ("usermod: UID
'998' already exists").
The system account is now moved to a free ID, so that the docker user takes the
ID of the host user. Its ID is changed in /etc/passwd: usermod would also change
the owner of the files of its home directory ("/").
Also rename a test that had the same name as another one (only the last one was run).
Fixes thecodingmachine#408
Merged
4 of 6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR fixes :
directory. On Ubuntu 24.04, IDs such as
998belong to system accounts of the image (systemd-network), and arealso the ID of the
gitlab-runneruser on many CI hosts: the commands were run with this account, which has nohome directory and no sudo (
touch ~/.startup_done: Permission denied). SettingDOCKER_USER=998failed too(
usermod: UID '998' already exists). The system account is now moved to a free ID, so that thedockerusertakes the host ID. Its ID is changed in
/etc/passwd:usermodwould also change the owner of the files of itshome directory (
/, including the mounted volume). Nothing changes for0,33(www-data),65534and theIDs that are not used in the image.
sudoin PHP proxy #253:sudo -u www-data php ...printed a sudo password error on each call, and failed withUnexpected PHP proxy outputwhen aPHP_*variable had changed. The proxy now runs PHP with the currentconfiguration when sudo is not available.
written in the output of the scripts generating the startup configuration: syntax error in
generated_conf.ini,supercronic exiting on a
bad crontab line, bash syntax errors in the startup commands. These scripts now sendPHP errors to stderr: the warnings are only logged.
Fixes #408
Fixes #253
Test plan (required)
New tests:
test_defaultUserTakesUidOfSystemAccountandtest_userWithoutSudoCanRunPhp(users-rights.sh),test_phpStartupWarning(tool-startup-command.sh). A test that had the same name as another one (only the last one was run) is renamedtest_defaultUserCanBeAnExistingUser.Checklist