From 6f66f93c46bb8b9836fb35c939d35ff0cd38e309 Mon Sep 17 00:00:00 2001 From: LaurinceG4N0 Date: Fri, 4 Sep 2026 18:01:51 +0100 Subject: [PATCH] Address review: targeted chown, fail-fast on non-writable dirs, drop stale HF cache mount Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_019sjWK7iyZbhCnUBACivQEy --- scripts/rocm-entrypoint.sh | 33 ++++++++++++++++++++++++++++----- 1 file changed, 28 insertions(+), 5 deletions(-) diff --git a/scripts/rocm-entrypoint.sh b/scripts/rocm-entrypoint.sh index 47b4686a..ef7452a3 100644 --- a/scripts/rocm-entrypoint.sh +++ b/scripts/rocm-entrypoint.sh @@ -18,10 +18,33 @@ done mkdir -p /home/voicebox/.cache/huggingface chown voicebox:voicebox /home/voicebox/.cache /home/voicebox/.cache/huggingface -# Ensure the mounted data volume is writable by the non-root user. -# The Dockerfile chowns /app/data at build time, but a runtime volume mount -# re-creates it owned by root, so fix ownership here (still root) before -# dropping privileges. -chown -R voicebox:voicebox /app/data || true +# Ensure the app data directories are writable by the non-root user. +# /app/data/generations is normally a host bind-mount, so never chown/chmod it: +# adopt the uid/gid that owns it instead, the same way we adopt the GPU groups +# above. The rest of /app/data lives in the image or a named volume and is ours +# to fix, so it gets chowned to match (dirs only, no -R on user content). +gen=/app/data/generations +mkdir -p "$gen" +gen_uid=$(stat -c %u "$gen") +gen_gid=$(stat -c %g "$gen") +if [ "$gen_uid" = 0 ]; then + # Docker created it for us; nothing on the host cares who owns it. + chown voicebox:voicebox "$gen" +elif [ "$gen_uid" != "$(id -u voicebox)" ]; then + getent group "$gen_gid" >/dev/null || groupadd -g "$gen_gid" hostdata + usermod -u "$gen_uid" -g "$gen_gid" voicebox + # Re-own what the old uid owned inside the image / named volume. + find /app/data -path "$gen" -prune -o -exec chown "$gen_uid:$gen_gid" {} + +fi + +for dir in /app/data/cache /app/data/profiles "$gen"; do + mkdir -p "$dir" + [ "$dir" = "$gen" ] || chown voicebox:voicebox "$dir" + gosu voicebox test -w "$dir" || { + echo "error: $dir is not writable by the voicebox user (uid $(id -u voicebox))" >&2 + [ "$dir" = "$gen" ] && echo "hint: make the host dir mounted there writable by that uid" >&2 + exit 1 + } +done exec gosu voicebox "$@"