From 25fd29caf955c55c8f74abb15c8ffd2479632aa4 Mon Sep 17 00:00:00 2001 From: mptyl Date: Tue, 11 Aug 2026 19:05:06 +0200 Subject: [PATCH] fix: expose real docker config to P2 image builds --- backend/scripts/p2-acceptance.mjs | 21 +++++++++++++++++++-- scripts/p2-acceptance.sh | 3 ++- 2 files changed, 21 insertions(+), 3 deletions(-) diff --git a/backend/scripts/p2-acceptance.mjs b/backend/scripts/p2-acceptance.mjs index 9ae080ba..e3bbafd4 100644 --- a/backend/scripts/p2-acceptance.mjs +++ b/backend/scripts/p2-acceptance.mjs @@ -1,6 +1,6 @@ #!/usr/bin/env node import { createHash, randomBytes } from "node:crypto"; -import { execFile } from "node:child_process"; +import { execFile, execFileSync } from "node:child_process"; import { promisify } from "node:util"; import { fileURLToPath } from "node:url"; import { createServer } from "node:http"; @@ -968,6 +968,15 @@ function sameSet(left, right) { return JSON.stringify([...left].sort()) === JSON.stringify([...right].sort()); } +function realUserHome(): string | undefined { + try { + const output = execFileSync("bash", ["-lc", 'printf "%s" ~'], { encoding: "utf8" }).trim(); + return output.length > 0 ? output : undefined; + } catch { + return undefined; + } +} + async function setupRealContext({ repositoryRoot = defaultRepositoryRoot, env = process.env }) { const run = await createOwnedRun({ repositoryRoot }); const provenance = await collectRepositoryProvenance({ repositoryRoot }); @@ -977,7 +986,15 @@ async function setupRealContext({ repositoryRoot = defaultRepositoryRoot, env = bashPath: resolveSystemExecutable("bash"), }; const pathValue = [...new Set([dirname(execs.gitPath), dirname(execs.dockerPath), "/usr/bin", "/bin", "/opt/homebrew/bin", "/usr/local/bin"])].join(":"); - const execEnv = buildSafeEnvironment({ ambient: env, fixture: { PATH: pathValue, HOME: run.root, TMPDIR: join(run.root, "tmp") } }); + // Docker CLI plugins (buildx) live under the real user's ~/.docker; the wrapper runs with a + // scrubbed environment, so derive the real home from the passwd entry and expose DOCKER_CONFIG. + const realHome = env.P2_REAL_HOME ?? realUserHome(); + const execEnv = buildSafeEnvironment({ ambient: env, fixture: { + PATH: pathValue, + HOME: run.root, + TMPDIR: join(run.root, "tmp"), + ...(realHome ? { DOCKER_CONFIG: join(realHome, ".docker") } : {}), + } }); const workspaceModules = await import("../dist/workspaces/registry.js").then(async (registryModule) => ({ WorkspaceRegistry: registryModule.WorkspaceRegistry, ...(await import("../dist/workspaces/schema.js")), diff --git a/scripts/p2-acceptance.sh b/scripts/p2-acceptance.sh index 0077062b..eda0a4f2 100755 --- a/scripts/p2-acceptance.sh +++ b/scripts/p2-acceptance.sh @@ -49,8 +49,9 @@ build_env=(/usr/bin/env -i "PATH=$owned_path" "HOME=$wrapper_root/home" "TMPDIR= /bin/rm -rf -- "$repo_root/backend/dist" "${build_env[@]}" "$node_path" "$npm_path" --prefix "$repo_root/backend" run build +p2_real_home=$(/bin/bash -lc 'printf "%s" ~' 2>/dev/null || true) safe_env=(/usr/bin/env -i "PATH=$owned_path" "HOME=$wrapper_root/home" "TMPDIR=$wrapper_root/tmp" - "P2_ACCEPTANCE_NODE_PATH=$node_path" "P2_ACCEPTANCE_NPM_PATH=$npm_path") + "P2_REAL_HOME=${p2_real_home:-}" "THT_BIN=$repo_root/harness/.venv/bin/tht" "P2_ACCEPTANCE_NODE_PATH=$node_path" "P2_ACCEPTANCE_NPM_PATH=$npm_path") set +e "${safe_env[@]}" "$node_path" "$repo_root/backend/scripts/p2-acceptance.mjs" "$@" status=$?