fix: expose real docker config to P2 image builds

This commit is contained in:
2026-08-11 19:05:06 +02:00
parent 7951891561
commit 25fd29caf9
2 changed files with 21 additions and 3 deletions
+19 -2
View File
@@ -1,6 +1,6 @@
#!/usr/bin/env node
import { createHash, randomBytes } from "node:crypto";
import { execFile } from "node:child_process";
import { execFile, execFileSync } from "node:child_process";
import { promisify } from "node:util";
import { fileURLToPath } from "node:url";
import { createServer } from "node:http";
@@ -968,6 +968,15 @@ function sameSet(left, right) {
return JSON.stringify([...left].sort()) === JSON.stringify([...right].sort());
}
function realUserHome(): string | undefined {
try {
const output = execFileSync("bash", ["-lc", 'printf "%s" ~'], { encoding: "utf8" }).trim();
return output.length > 0 ? output : undefined;
} catch {
return undefined;
}
}
async function setupRealContext({ repositoryRoot = defaultRepositoryRoot, env = process.env }) {
const run = await createOwnedRun({ repositoryRoot });
const provenance = await collectRepositoryProvenance({ repositoryRoot });
@@ -977,7 +986,15 @@ async function setupRealContext({ repositoryRoot = defaultRepositoryRoot, env =
bashPath: resolveSystemExecutable("bash"),
};
const pathValue = [...new Set([dirname(execs.gitPath), dirname(execs.dockerPath), "/usr/bin", "/bin", "/opt/homebrew/bin", "/usr/local/bin"])].join(":");
const execEnv = buildSafeEnvironment({ ambient: env, fixture: { PATH: pathValue, HOME: run.root, TMPDIR: join(run.root, "tmp") } });
// Docker CLI plugins (buildx) live under the real user's ~/.docker; the wrapper runs with a
// scrubbed environment, so derive the real home from the passwd entry and expose DOCKER_CONFIG.
const realHome = env.P2_REAL_HOME ?? realUserHome();
const execEnv = buildSafeEnvironment({ ambient: env, fixture: {
PATH: pathValue,
HOME: run.root,
TMPDIR: join(run.root, "tmp"),
...(realHome ? { DOCKER_CONFIG: join(realHome, ".docker") } : {}),
} });
const workspaceModules = await import("../dist/workspaces/registry.js").then(async (registryModule) => ({
WorkspaceRegistry: registryModule.WorkspaceRegistry,
...(await import("../dist/workspaces/schema.js")),
+2 -1
View File
@@ -49,8 +49,9 @@ build_env=(/usr/bin/env -i "PATH=$owned_path" "HOME=$wrapper_root/home" "TMPDIR=
/bin/rm -rf -- "$repo_root/backend/dist"
"${build_env[@]}" "$node_path" "$npm_path" --prefix "$repo_root/backend" run build
p2_real_home=$(/bin/bash -lc 'printf "%s" ~' 2>/dev/null || true)
safe_env=(/usr/bin/env -i "PATH=$owned_path" "HOME=$wrapper_root/home" "TMPDIR=$wrapper_root/tmp"
"P2_ACCEPTANCE_NODE_PATH=$node_path" "P2_ACCEPTANCE_NPM_PATH=$npm_path")
"P2_REAL_HOME=${p2_real_home:-}" "THT_BIN=$repo_root/harness/.venv/bin/tht" "P2_ACCEPTANCE_NODE_PATH=$node_path" "P2_ACCEPTANCE_NPM_PATH=$npm_path")
set +e
"${safe_env[@]}" "$node_path" "$repo_root/backend/scripts/p2-acceptance.mjs" "$@"
status=$?