#!/usr/bin/env bash # Execute the documented server ownership model with distinct runtime and human operator IDs. set -euo pipefail root="$(cd "$(dirname "$0")/.." && pwd -P)" image='golang:1.26.5-bookworm@sha256:1ecb7edf62a0408027bd5729dfd6b1b8766e578e8df93995b225dfd0944eb651' docker run --rm --volume "$root:/repository:ro" "$image" /bin/bash -ceu ' groupadd --gid 10001 thothii useradd --uid 10001 --gid 10001 --home-dir /srv/thothii --create-home --shell /usr/sbin/nologin thothii # Reproduce the conservative home mode permitted by the documented useradd sequence. chmod 0700 /srv/thothii groupadd --gid 20001 operator-primary groupadd --gid 20002 thothii-ops groupadd --gid 20003 docker useradd --uid 20001 --gid 20001 --groups 20002,20003 --create-home --shell /bin/bash operator install -d -o 10001 -g 20002 -m 2750 /srv/thothii install -d -o 10001 -g 20002 -m 2750 /srv/thothii/source install -d -o 10001 -g 20002 -m 2770 /srv/thothii/operator install -d -o 10001 -g 20002 -m 2750 /srv/thothii/secrets install -d -o 10001 -g 10001 -m 0750 /srv/thothii/data /srv/thothii/pi-state /srv/thothii/workspace-registry install -d -o 10001 -g 10001 -m 0700 /srv/thothii/data/workspace-secrets install -d -o 10001 -g 20002 -m 2750 /srv/thothii/source/ThothII /srv/thothii/source/ThothII/scripts install -o 10001 -g 20002 -m 0750 /repository/scripts/build-thothctl.sh /srv/thothii/source/ThothII/scripts/build-thothctl.sh install -o 10001 -g 20002 -m 0750 /repository/scripts/prepare-server-pi-state.sh /srv/thothii/source/ThothII/scripts/prepare-server-pi-state.sh /srv/thothii/source/ThothII/scripts/prepare-server-pi-state.sh /srv/thothii/pi-state 10001 10001 printf "%s\n" "PLACEHOLDER=replace-me" > /srv/thothii/operator/server.env printf "%s\n" "projectDirectory: replace-me" > /srv/thothii/operator/thothii-installation.yaml chown 10001:20002 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml chmod 0660 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml printf "%s\n" \ "#!/bin/bash" \ "set -euo pipefail" \ "if [[ \"\${1:-}\" == build ]]; then" \ " destination=; for argument in \"\$@\"; do case \"\$argument\" in type=local,dest=*) destination=\"\${argument#type=local,dest=}\" ;; esac; done" \ " test -n \"\$destination\"; mkdir -p \"\$destination\"" \ " printf \"%s\\n\" \"#!/bin/bash\" \"set -euo pipefail\" \"test -r \\\"\\\$2\\\"\" \"docker compose up --detach\" > \"\$destination/thothctl-linux-amd64\"" \ " chmod 0750 \"\$destination/thothctl-linux-amd64\"; exit 0" \ "fi" \ "test \"\${1:-}\" = compose; : > /srv/thothii/operator/start.marker" \ > /usr/local/bin/docker chmod 0755 /usr/local/bin/docker runuser --user operator -- /bin/bash -ceu '\'' umask 0007 sed -i "s/replace-me/ready/" /srv/thothii/operator/server.env sed -i "s#replace-me#/srv/thothii/source/ThothII#" /srv/thothii/operator/thothii-installation.yaml for protected in /srv/thothii /srv/thothii/source /srv/thothii/secrets \ /srv/thothii/data /srv/thothii/pi-state /srv/thothii/workspace-registry; do if touch "$protected/operator-must-not-write" 2>/dev/null; then exit 42; fi done THT_THOTHCTL_OUTPUT_DIRECTORY=/srv/thothii/operator/build-output \ /srv/thothii/source/ThothII/scripts/build-thothctl.sh if THT_THOTHCTL_OUTPUT_DIRECTORY=relative-output \ /srv/thothii/source/ThothII/scripts/build-thothctl.sh 2>/dev/null; then exit 44; fi root_output_error=/srv/thothii/operator/root-output.error if THT_THOTHCTL_OUTPUT_DIRECTORY=/ \ /srv/thothii/source/ThothII/scripts/build-thothctl.sh 2>"$root_output_error"; then exit 45; fi grep -Fq "THT_THOTHCTL_OUTPUT_DIRECTORY must be an absolute canonical path" \ "$root_output_error" || exit 46 rm -f "$root_output_error" /srv/thothii/operator/build-output/thothctl-linux-amd64 \ --installation /srv/thothii/operator/thothii-installation.yaml start '\'' test "$(stat -c %u:%g /srv/thothii)" = 10001:20002 test "$(stat -c %a /srv/thothii)" = 2750 test "$(stat -c %u:%g /srv/thothii/pi-state/agent)" = 10001:10001 test "$(stat -c %a /srv/thothii/pi-state/agent)" = 700 for target in auth.json models.json settings.json; do test "$(stat -c %u:%g /srv/thothii/pi-state/agent/$target)" = 10001:10001 test "$(stat -c %a /srv/thothii/pi-state/agent/$target)" = 600 done test "$(stat -c %u:%g /srv/thothii/operator/build-output/thothctl-linux-amd64)" = 20001:20002 test "$(stat -c %a /srv/thothii/operator/build-output/thothctl-linux-amd64)" = 750 test -f /srv/thothii/operator/start.marker for protected in /srv/thothii /srv/thothii/source /srv/thothii/secrets \ /srv/thothii/data /srv/thothii/pi-state /srv/thothii/workspace-registry; do test ! -e "$protected/operator-must-not-write" done ' echo "distinct server operator UID/GID fixture passed"