Skip to content

fix(docker): ensure ironclaw runtime home exists - #1918

Merged
serrrfirat merged 2 commits into
stagingfrom
emdash/fix-missing-home-directory-6ua
Apr 6, 2026
Merged

serrrfirat merged 2 commits into
stagingfrom
emdash/fix-missing-home-directory-6ua

Conversation

@serrrfirat

Copy link
Copy Markdown
Collaborator

Summary

  • set an explicit HOME=/home/ironclaw in the production runtime image
  • pre-create /home/ironclaw/.ironclaw and switch WORKDIR to the ironclaw home before dropping privileges
  • add a regression test that locks in the runtime Dockerfile home-directory invariants

Testing

  • rustfmt --check tests/dockerfile_runtime_home.rs
  • rustc --test tests/dockerfile_runtime_home.rs -o /tmp/dockerfile_runtime_home_test && /tmp/dockerfile_runtime_home_test

Notes

  • cargo test --test dockerfile_runtime_home was attempted, but this machine ran out of disk during workspace compilation before the test binary was built.
  • Local Docker daemon was unavailable, so I could not run a container smoke test here.

Fixes #1899

@github-actions github-actions Bot added the scope: sandbox Docker sandbox label Apr 2, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Dockerfile to establish a home directory for the ironclaw user and sets the working directory to that location. It also introduces a new test suite to verify these Dockerfile configurations. Review feedback identifies a potential runtime issue where the application might fail to find migrations due to the changed working directory and suggests improving the robustness of the new tests by using token-based matching instead of fragile string containment.

Comment thread Dockerfile
RUN useradd -m -u 1000 -s /bin/bash ironclaw \
&& mkdir -p /home/ironclaw/.ironclaw \
&& chown -R ironclaw:ironclaw /home/ironclaw
WORKDIR /home/ironclaw

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The WORKDIR is set to /home/ironclaw, but the application migrations are copied to /app/migrations (line 72). If the ironclaw binary expects to find the migrations directory in its current working directory (e.g., via a relative path like ./migrations), it will fail to locate them. Consider either setting the WORKDIR to /app or ensuring the application is configured to use the absolute path /app/migrations to avoid runtime errors during database initialization.

Comment on lines +16 to +31
assert!(
dockerfile.contains("useradd -m -u 1000 -s /bin/bash ironclaw"),
"runtime image must create the ironclaw user with a home directory",
);
assert!(
dockerfile.contains("ENV HOME=/home/ironclaw"),
"runtime image must set HOME to /home/ironclaw for ~/.ironclaw state",
);
assert!(
dockerfile.contains("WORKDIR /home/ironclaw"),
"runtime image must start in the ironclaw home directory",
);
assert!(
dockerfile.contains("mkdir -p /home/ironclaw/.ironclaw"),
"runtime image must pre-create ~/.ironclaw before dropping privileges",
);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

These assertions are highly sensitive to the exact string content of the Dockerfile. To improve robustness and maintainability, use token-based or word-boundary checks instead of simple substring containment to avoid false positives. Additionally, separate checks for distinct conditions (like username and flags) to improve code clarity and robustness, as per repository guidelines.

References
  1. When detecting commands or keywords in a string, use token-based or word-boundary checks instead of simple substring containment to avoid false positives.
  2. Separate checks for distinct conditions to improve code clarity and robustness.

@serrrfirat
serrrfirat requested a review from zmanian April 3, 2026 08:28
…-home-directory-6ua

# Conflicts:
#	Dockerfile
@github-actions github-actions Bot added scope: channel/cli TUI / CLI channel size: S 10-49 changed lines risk: low Changes to docs, tests, or low-risk modules contributor: experienced 6-19 merged PRs labels Apr 3, 2026

@zmanian zmanian left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Clean, minimal fix for a real runtime issue.

Dockerfile changes: Correct. Setting HOME explicitly, pre-creating ~/.ironclaw, and chown-ing before USER ironclaw is the right approach. The useradd -m -d flags are consistent. Idempotent -- safe to rebuild.

Gemini's migration concern is a false positive: migrations use embed_migrations!("migrations") (refinery macro) which embeds SQL at compile time into the binary. The WORKDIR change has no effect on migration discovery at runtime. /app/migrations is only needed during the build stage.

Test (tests/dockerfile_runtime_home.rs): Reasonable regression guard for a Dockerfile invariant. The string-matching approach is brittle by nature, but for this purpose (catching accidental removal of the home dir setup) it is adequate. Gemini's suggestion to use "token-based matching" is over-engineering for a Dockerfile text check.

Snapshot diff: Whitespace-only change (trailing space removed). No functional impact.

One minor observation (non-blocking): the PR drops -s /bin/bash from the useradd call that exists on staging. The default shell will be /bin/sh or whatever is in /etc/default/useradd. This is fine for a container runtime (the ironclaw process doesn't need an interactive shell), but worth noting in case anyone expects bash inside the container for debugging.

@serrrfirat
serrrfirat merged commit 13852ff into staging Apr 6, 2026
14 checks passed
@serrrfirat
serrrfirat deleted the emdash/fix-missing-home-directory-6ua branch April 6, 2026 06:22
This was referenced Apr 6, 2026
drchirag1991 pushed a commit to drchirag1991/ironclaw that referenced this pull request Apr 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: experienced 6-19 merged PRs risk: low Changes to docs, tests, or low-risk modules scope: channel/cli TUI / CLI channel scope: sandbox Docker sandbox size: S 10-49 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[CRITICAL] Missing home directory for ironclaw user will cause runtime failures. `adduser -

2 participants