From d49c644b611a7cc50f19fd40f30464ec0a12d2db Mon Sep 17 00:00:00 2001 From: mptyl Date: Tue, 25 Aug 2026 23:46:32 +0200 Subject: [PATCH] fix(deploy): prepare server auth root before configure --- scripts/test-task13-runtime-fixtures.sh | 14 ++++++++++++++ scripts/unified-deployment-smoke.sh | 11 +++++++++++ 2 files changed, 25 insertions(+) diff --git a/scripts/test-task13-runtime-fixtures.sh b/scripts/test-task13-runtime-fixtures.sh index 501a0107..80db3d4f 100755 --- a/scripts/test-task13-runtime-fixtures.sh +++ b/scripts/test-task13-runtime-fixtures.sh @@ -80,6 +80,20 @@ else TASK13_SESSION_PASSWORD="fixture-private-token-$profile" TASK13_SESSION_MIGRATOR_PASSWORD="fixture-migrator-token-$profile" task13_write_server_fixture_files + original_task13_run_logged="$(declare -f task13_run_logged)" + ownership_calls="$fixture/server-auth-ownership.calls" + task13_run_logged() { + printf '%s\n' "$*" >"$ownership_calls" + } + task13_prepare_server_auth_canonical_root + grep -Fxq -- \ + "prepare server authentication canonical root sudo -n -- install -d -o 0 -g 0 -m 0700 -- $TASK13_AUTH_ROOT" \ + "$ownership_calls" || { + echo "server auth fixture does not prepare a root-owned private canonical directory" >&2 + exit 1 + } + unset -f task13_run_logged + eval "$original_task13_run_logged" compose_files=( -f "$root/compose.yaml" -f "$root/deploy/compose.server.yaml" diff --git a/scripts/unified-deployment-smoke.sh b/scripts/unified-deployment-smoke.sh index 138bffe1..f7ebb1ea 100755 --- a/scripts/unified-deployment-smoke.sh +++ b/scripts/unified-deployment-smoke.sh @@ -944,6 +944,16 @@ task13_configure_server_oidc_authentication() { --authentik-base-url "https://task13-fake-oidc:9443" --user-group task13-users --admin-group task13-admins } +task13_prepare_server_auth_canonical_root() { + [[ "${TASK13_PROFILE:-}" == server \ + && "$TASK13_AUTH_ROOT" == "$TASK13_TMP/auth" \ + && ! -L "$TASK13_AUTH_ROOT" \ + && ( ! -e "$TASK13_AUTH_ROOT" || -d "$TASK13_AUTH_ROOT" ) ]] \ + || task13_fail "refusing to prepare an unexpected server authentication root" + task13_run_logged "prepare server authentication canonical root" sudo -n -- \ + install -d -o 0 -g 0 -m 0700 -- "$TASK13_AUTH_ROOT" +} + task13_prepare_local_auth_runtime() { local owner_label owner_label="$(docker volume inspect --format '{{ index .Labels "io.thothii.task13.run" }}' \ @@ -2844,6 +2854,7 @@ task13_server_smoke_main() { task13_write_server_fixture_files task13_seed_registry task13_build_tht + task13_prepare_server_auth_canonical_root task13_configure_server_oidc_authentication task13_start_server_stack task13_record_project_image_evidence