fix: remove stale {{WORKSPACE_NAME}} directory from container home

Older cached images still contain a literal /home/user/{{WORKSPACE_NAME}}
directory baked in by the previous Dockerfile generation. Even though new
images no longer create it, existing images leave the placeholder folder
alongside the real repo-named mount.

- Add entrypoint cleanup that removes /{{WORKSPACE_NAME}} if it
  exists before creating the real workspace target and /workspace symlink
- Update unit tests to assert the stale placeholder removal

Quality gates:
- pytest tests/unit: 212 passed
- ruff: clean on changed files
- mypy: clean on changed files
This commit is contained in:
Developer
2026-06-15 08:41:27 +00:00
parent 41f9427224
commit 90992e46a8
17 changed files with 46 additions and 26 deletions
+1 -1
View File
@@ -2,7 +2,7 @@
dir: openspec/changes
## role
Provides change-tracking and diffing utilities for OpenAPI specification evolution and version comparison.
Manages change tracking, versioning, and history for OpenAPI specification modifications
## parent
index: openspec/.pi-map.index.md
map: openspec/.pi-map.md
@@ -2,7 +2,7 @@
dir: openspec/changes/fix-pi-container-mount-permissions
## role
Documents a bug fix for resolving permission issues with Pi container repository mounts and npm updates in a configurable home directory environment.
Documents a bug fix for container mount path permissions in a Raspberry Pi agent development environment.
## parent
index: openspec/changes/.pi-map.index.md
map: openspec/changes/.pi-map.md
@@ -4,14 +4,14 @@ dir: openspec/changes/fix-pi-container-mount-permissions
index: openspec/changes/fix-pi-container-mount-permissions/.pi-map.index.md
## role
Documents a bug fix for resolving permission issues with Pi container repository mounts and npm updates in a configurable home directory environment.
Documents a bug fix for container mount path permissions in a Raspberry Pi agent development environment.
## files
- change.md | Documents a bug fix for pi-agent container repository mount paths and npm update permissions in a configurable home directory system. | dep: Alembic, manifest_compiler.py, instance_service.py, Docker compose, npm, pytest
- change.md | Documents a bug fix for pi-agent container repository mount paths and npm update permissions in a containerized development environment. | dep: Alembic, Docker/container tooling, npm, Python (manifest_compiler.py, instance_service.py), pytest
- tasks.md | Tracks completion status of tasks for fixing a Pi container repository mount and npm update permissions issue
## arch
Change-request documentation pattern using markdown files for specification (change.md) and task tracking (tasks.md) with checkbox-based completion status.
Simple documentation-based change tracking using markdown files (change.md for specifications, tasks.md for progress tracking) without code implementation.
## tags
npm, tasks, container, repository, mount, update, permissions, py
npm, tasks, container, repository, mount, update, permissions, change
## symbols
-
## workflows
@@ -11,6 +11,7 @@ After implementing configurable tool container home directories, new `pi-agent`
3. The generated entrypoint hardcodes the literal string `{{WORKSPACE_NAME}}` as the symlink target.
4. `npm_global` packages are installed with `RUN npm install -g ...` as root into the system npm prefix, so the non-root container user cannot update them.
5. Once the repo mount moves out of `/workspace`, the generated `/workspace` compatibility symlink is created in the image as root. The non-root entrypoint cannot replace it (write permission is required on `/`), so container startup fails.
6. Older images baked a literal `{{WORKSPACE_NAME}}` directory into `/home/user`, which survives alongside the real repo-named mount directory.
## Fix
@@ -24,6 +25,9 @@ After implementing configurable tool container home directories, new `pi-agent`
- Generate the entrypoint symlink from the runtime `WORKSPACE_NAME` environment variable.
- Install `npm_global` packages into a user-writable prefix (`{home_dir}/.npm-global`) and add it to `PATH`.
- Use `sudo` or root to create the `/workspace` compatibility symlink, because `/` is owned by root and the non-root entrypoint cannot replace a root-owned symlink.
- Start the container as root and drop privileges to the container user inside the entrypoint via `su`.
- Do not create mount target directories or the `/workspace` symlink in the image when they depend on the runtime `{{WORKSPACE_NAME}}` placeholder.
- Remove any stale literal `{{WORKSPACE_NAME}}` directory left over from older images at container startup.
3. Update `instance_service.py` to pass `REPO_NAME` and `WORKSPACE_NAME` into manifest compilation.
4. Update unit tests for the new behavior.