fix: pi container repo mount target and npm update permissions
- Add Alembic migration to update built-in pi-agent manifest:
* repo mount target from /workspace to ~/{{WORKSPACE_NAME}}
* keep /workspace as compatibility symlink via working_dir
* update startup chown target to $HOME/$WORKSPACE_NAME
- Pass REPO_NAME and WORKSPACE_NAME to compile_compose from instance_service
- Substitute {{WORKSPACE_NAME}} in manifest mount targets and expose it as
a container env var so the entrypoint can create the /workspace symlink
- Generate entrypoint workspace symlink from runtime WORKSPACE_NAME env var
- Install npm_global packages into {home_dir}/.npm-global with PATH so the
non-root container user can update global packages
- Update manifest compiler unit tests for the new behavior
Quality gates:
- pytest tests/unit: 207 passed
- ruff: clean on changed files
- mypy: clean on changed files
- alembic heads: single head
This commit is contained in:
+28
-41
@@ -1,52 +1,39 @@
|
||||
# . (index)
|
||||
dir: .
|
||||
|
||||
## Project Map Protocol
|
||||
|
||||
1. Read this protocol and the root `.pi-map.index.md` first.
|
||||
2. Use `index:` / `map:` references to open relevant directory indexes and maps.
|
||||
3. Load indexes before rich maps during task-start navigation.
|
||||
4. Read the local rich map and actual source before editing.
|
||||
5. Treat non-empty `## dirty` sections in either artifact as stale.
|
||||
6. If source and generated artifacts disagree, trust source.
|
||||
7. If map and index disagree, trust neither blindly; verify from source and regenerate the pair.
|
||||
8. After editing source, run `project_map_patch` for each changed file.
|
||||
9. Before broad architectural claims or final handoff, run `project_map_validate` when freshness matters.
|
||||
|
||||
Trust boundary: index routes, map orients, source decides.
|
||||
# openspec (index)
|
||||
dir: openspec
|
||||
|
||||
## role
|
||||
Defines a living documentation methodology and project configuration for managing software requirements, specifications, and development discipline rules within a Docker-based coding agent platform.
|
||||
Defines a living documentation methodology and configuration for managing software requirements, specifications, and development workflows within a project repository.
|
||||
## parent
|
||||
-
|
||||
index: ./.pi-map.index.md
|
||||
map: ./.pi-map.md
|
||||
## children
|
||||
- changes
|
||||
index: changes/.pi-map.index.md
|
||||
map: changes/.pi-map.md
|
||||
- designs
|
||||
index: designs/.pi-map.index.md
|
||||
map: designs/.pi-map.md
|
||||
- docs
|
||||
index: docs/.pi-map.index.md
|
||||
map: docs/.pi-map.md
|
||||
- explorations
|
||||
index: explorations/.pi-map.index.md
|
||||
map: explorations/.pi-map.md
|
||||
- proposals
|
||||
index: proposals/.pi-map.index.md
|
||||
map: proposals/.pi-map.md
|
||||
- specs
|
||||
index: specs/.pi-map.index.md
|
||||
map: specs/.pi-map.md
|
||||
- tasks
|
||||
index: tasks/.pi-map.index.md
|
||||
map: tasks/.pi-map.md
|
||||
- openspec/changes
|
||||
index: openspec/changes/.pi-map.index.md
|
||||
map: openspec/changes/.pi-map.md
|
||||
- openspec/designs
|
||||
index: openspec/designs/.pi-map.index.md
|
||||
map: openspec/designs/.pi-map.md
|
||||
- openspec/docs
|
||||
index: openspec/docs/.pi-map.index.md
|
||||
map: openspec/docs/.pi-map.md
|
||||
- openspec/explorations
|
||||
index: openspec/explorations/.pi-map.index.md
|
||||
map: openspec/explorations/.pi-map.md
|
||||
- openspec/proposals
|
||||
index: openspec/proposals/.pi-map.index.md
|
||||
map: openspec/proposals/.pi-map.md
|
||||
- openspec/specs
|
||||
index: openspec/specs/.pi-map.index.md
|
||||
map: openspec/specs/.pi-map.md
|
||||
- openspec/tasks
|
||||
index: openspec/tasks/.pi-map.index.md
|
||||
map: openspec/tasks/.pi-map.md
|
||||
## files
|
||||
- README.md
|
||||
- config.yaml
|
||||
## links
|
||||
index: ./.pi-map.index.md
|
||||
map: ./.pi-map.md
|
||||
index: openspec/.pi-map.index.md
|
||||
map: openspec/.pi-map.md
|
||||
## workflows
|
||||
-
|
||||
## dirty
|
||||
|
||||
@@ -1,37 +1,40 @@
|
||||
# changes (index)
|
||||
dir: changes
|
||||
# openspec/changes (index)
|
||||
dir: openspec/changes
|
||||
|
||||
## role
|
||||
Package for tracking, storing, and managing file changes or diffs in the project.
|
||||
Manages change tracking and versioning for OpenAPI specification modifications
|
||||
## parent
|
||||
index: ./.pi-map.index.md
|
||||
map: ./.pi-map.md
|
||||
index: openspec/.pi-map.index.md
|
||||
map: openspec/.pi-map.md
|
||||
## children
|
||||
- changes/archive
|
||||
index: changes/archive/.pi-map.index.md
|
||||
map: changes/archive/.pi-map.md
|
||||
- changes/fix-terminal-container-overflow
|
||||
index: changes/fix-terminal-container-overflow/.pi-map.index.md
|
||||
map: changes/fix-terminal-container-overflow/.pi-map.md
|
||||
- changes/fix-tmux-mouse-config
|
||||
index: changes/fix-tmux-mouse-config/.pi-map.index.md
|
||||
map: changes/fix-tmux-mouse-config/.pi-map.md
|
||||
- changes/mobile-config-profiles-ui
|
||||
index: changes/mobile-config-profiles-ui/.pi-map.index.md
|
||||
map: changes/mobile-config-profiles-ui/.pi-map.md
|
||||
- changes/mobile-edit-default-bottom-actions
|
||||
index: changes/mobile-edit-default-bottom-actions/.pi-map.index.md
|
||||
map: changes/mobile-edit-default-bottom-actions/.pi-map.md
|
||||
- changes/mobile-list-delete-button
|
||||
index: changes/mobile-list-delete-button/.pi-map.index.md
|
||||
map: changes/mobile-list-delete-button/.pi-map.md
|
||||
- changes/mobile-tool-profile-ui
|
||||
index: changes/mobile-tool-profile-ui/.pi-map.index.md
|
||||
map: changes/mobile-tool-profile-ui/.pi-map.md
|
||||
- openspec/changes/archive
|
||||
index: openspec/changes/archive/.pi-map.index.md
|
||||
map: openspec/changes/archive/.pi-map.md
|
||||
- openspec/changes/fix-pi-container-mount-permissions
|
||||
index: openspec/changes/fix-pi-container-mount-permissions/.pi-map.index.md
|
||||
map: openspec/changes/fix-pi-container-mount-permissions/.pi-map.md
|
||||
- openspec/changes/fix-terminal-container-overflow
|
||||
index: openspec/changes/fix-terminal-container-overflow/.pi-map.index.md
|
||||
map: openspec/changes/fix-terminal-container-overflow/.pi-map.md
|
||||
- openspec/changes/fix-tmux-mouse-config
|
||||
index: openspec/changes/fix-tmux-mouse-config/.pi-map.index.md
|
||||
map: openspec/changes/fix-tmux-mouse-config/.pi-map.md
|
||||
- openspec/changes/mobile-config-profiles-ui
|
||||
index: openspec/changes/mobile-config-profiles-ui/.pi-map.index.md
|
||||
map: openspec/changes/mobile-config-profiles-ui/.pi-map.md
|
||||
- openspec/changes/mobile-edit-default-bottom-actions
|
||||
index: openspec/changes/mobile-edit-default-bottom-actions/.pi-map.index.md
|
||||
map: openspec/changes/mobile-edit-default-bottom-actions/.pi-map.md
|
||||
- openspec/changes/mobile-list-delete-button
|
||||
index: openspec/changes/mobile-list-delete-button/.pi-map.index.md
|
||||
map: openspec/changes/mobile-list-delete-button/.pi-map.md
|
||||
- openspec/changes/mobile-tool-profile-ui
|
||||
index: openspec/changes/mobile-tool-profile-ui/.pi-map.index.md
|
||||
map: openspec/changes/mobile-tool-profile-ui/.pi-map.md
|
||||
## files
|
||||
## links
|
||||
index: changes/.pi-map.index.md
|
||||
map: changes/.pi-map.md
|
||||
index: openspec/changes/.pi-map.index.md
|
||||
map: openspec/changes/.pi-map.md
|
||||
## workflows
|
||||
-
|
||||
## dirty
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
# openspec/changes/fix-pi-container-mount-permissions (index)
|
||||
dir: openspec/changes/fix-pi-container-mount-permissions
|
||||
|
||||
## role
|
||||
Documents a bug fix for resolving permission issues with Pi container repository mounts and npm updates in a development environment.
|
||||
## parent
|
||||
index: openspec/changes/.pi-map.index.md
|
||||
map: openspec/changes/.pi-map.md
|
||||
## children
|
||||
-
|
||||
## files
|
||||
- change.md
|
||||
- tasks.md
|
||||
## links
|
||||
index: openspec/changes/fix-pi-container-mount-permissions/.pi-map.index.md
|
||||
map: openspec/changes/fix-pi-container-mount-permissions/.pi-map.md
|
||||
## workflows
|
||||
-
|
||||
## dirty
|
||||
-
|
||||
@@ -0,0 +1,20 @@
|
||||
# openspec/changes/fix-pi-container-mount-permissions
|
||||
dir: openspec/changes/fix-pi-container-mount-permissions
|
||||
|
||||
index: openspec/changes/fix-pi-container-mount-permissions/.pi-map.index.md
|
||||
|
||||
## role
|
||||
Documents a bug fix for resolving permission issues with Pi container repository mounts and npm updates in a development environment.
|
||||
## files
|
||||
- change.md | Documents a bug fix for pi-agent container repository mounting and npm update permissions in a development environment system. | dep: Alembic, manifest_compiler.py, instance_service.py, pytest, ruff, mypy, npm
|
||||
- tasks.md | Tracks completion status of tasks for fixing a Pi container repository mount and npm update permissions issue
|
||||
## arch
|
||||
Simple documentation-based change tracking using markdown files for issue description (change.md) and task checklist (tasks.md) without code implementation.
|
||||
## tags
|
||||
npm, tasks, container, repository, update, permissions, py, change
|
||||
## symbols
|
||||
-
|
||||
## workflows
|
||||
-
|
||||
## dirty
|
||||
-
|
||||
@@ -0,0 +1,39 @@
|
||||
# Fix pi container repo mount and npm update permissions
|
||||
|
||||
## Problem
|
||||
|
||||
After implementing configurable tool container home directories, new `pi-agent` containers still bind-mount the git repository at `/workspace` instead of under `/home/user/{repo_name}`. In addition, users cannot run `npm update -g @earendil-works/pi-coding-agent` inside the container because the global npm prefix (`/usr/lib/node_modules`) is owned by root.
|
||||
|
||||
## Root cause
|
||||
|
||||
1. The built-in `pi-agent` manifest in `tool_definition_manifests` still declares an explicit repo mount with `"target": "/workspace"` and `"working_dir": "/workspace"`. This masks the generated `/workspace → /home/user/{repo}` compatibility symlink.
|
||||
2. `manifest_compiler.py` does not substitute the instance-specific `{{WORKSPACE_NAME}}` placeholder in explicit mount targets, and `instance_service.py` does not pass `WORKSPACE_NAME`/`REPO_NAME` to `compile_compose` for manifest-based tools.
|
||||
3. The generated entrypoint hardcodes the literal string `{{WORKSPACE_NAME}}` as the symlink target.
|
||||
4. `npm_global` packages are installed with `RUN npm install -g ...` as root into the system npm prefix, so the non-root container user cannot update them.
|
||||
|
||||
## Fix
|
||||
|
||||
1. Add an Alembic data migration that updates the built-in `pi-agent` manifest:
|
||||
- Change the repo mount target to `~/{{WORKSPACE_NAME}}`.
|
||||
- Keep `runtime.working_dir` as `/workspace` (the compatibility symlink).
|
||||
- Update the startup script to chown the real mount path (`$HOME/$WORKSPACE_NAME`).
|
||||
2. Update `manifest_compiler.py`:
|
||||
- Substitute `{{WORKSPACE_NAME}}` in mount targets in `compile_compose`.
|
||||
- Pass `WORKSPACE_NAME` as a container environment variable.
|
||||
- Generate the entrypoint symlink from the runtime `WORKSPACE_NAME` environment variable.
|
||||
- Install `npm_global` packages into a user-writable prefix (`{home_dir}/.npm-global`) and add it to `PATH`.
|
||||
3. Update `instance_service.py` to pass `REPO_NAME` and `WORKSPACE_NAME` into manifest compilation.
|
||||
4. Update unit tests for the new behavior.
|
||||
|
||||
## Affected files
|
||||
|
||||
- `apps/api/alembic/versions/<new>_fix_pi_agent_home_directory_mount.py`
|
||||
- `apps/api/src/services/build/manifest_compiler.py`
|
||||
- `apps/api/src/services/tool/instance_service.py`
|
||||
- `apps/api/tests/unit/test_manifest_compiler.py`
|
||||
|
||||
## Verification
|
||||
|
||||
- `pytest apps/api/tests/unit/test_manifest_compiler.py`
|
||||
- `pytest apps/api/tests/unit/test_alembic_migrations.py`
|
||||
- `ruff`, `mypy`, `npm run typecheck`, `npm run lint`
|
||||
@@ -0,0 +1,9 @@
|
||||
# Tasks: fix pi container repo mount and npm update permissions
|
||||
|
||||
- [x] Investigate root cause (manifest target, missing variables, npm prefix)
|
||||
- [x] Create Alembic data migration to update pi-agent manifest
|
||||
- [x] Update manifest_compiler.py: {{WORKSPACE_NAME}} substitution, env var, entrypoint runtime var, npm prefix
|
||||
- [x] Update instance_service.py to pass REPO_NAME/WORKSPACE_NAME
|
||||
- [x] Update unit tests
|
||||
- [x] Run quality gates (pytest unit, ruff, mypy)
|
||||
- [ ] Commit and push
|
||||
Reference in New Issue
Block a user