fix: check root before sudo when creating /workspace symlink

The previous ordering checked SUDO before checking if the process was
already running as root. When Docker starts the container with a
non-root user, SUDO may be empty, but the real fix is that the
entrypoint should try root first (e.g. when the image is started as
root) and only then fall back to sudo.

- Reorder symlink creation logic: root first, then sudo, then best-effort
- Update unit test to assert root is checked before sudo

Quality gates:
- pytest tests/unit: 208 passed
- ruff: clean on changed files
- mypy: clean on changed files
This commit is contained in:
Developer
2026-06-14 21:25:41 +00:00
parent bd94cc9bbf
commit 47de2a0133
12 changed files with 37 additions and 30 deletions
+2 -2
View File
@@ -4,10 +4,10 @@ dir: apps
index: apps/.pi-map.index.md
## role
Contains the main application entry points and executable modules for the project.
Contains the deployable application entry points and executable configurations for the project.
## files
## arch
Modular application architecture with separate deployable units, likely following microservices or layered architecture patterns with domain-driven organization.
Multi-app workspace structure with separate application boundaries, likely following micro-frontend or modular monolith patterns where each sub-directory represents an independent deployable unit.
## tags
-
## symbols