Files
headquarter/openspec/changes/fix-pi-container-mount-permissions/change.md
T
Developer bd94cc9bbf fix: use sudo/root to create /workspace symlink in manifest entrypoint
The previous commit moved the pi-agent repo mount from /workspace to
/home/user/{repo_name}. This exposed a permission bug: the Dockerfile
creates /workspace as a root-owned symlink in the image, and the
non-root entrypoint could not replace it because / is owned by root.

- Update compile_entrypoint to recreate /workspace via sudo when running
  as the container user, or directly when running as root
- Add unit test covering sudo/root symlink creation
- Update OpenSpec change docs with the additional root cause

Quality gates:
- pytest tests/unit: 208 passed
- ruff: clean on changed files
- mypy: clean on changed files
- alembic heads: single head
2026-06-14 20:29:03 +00:00

2.8 KiB

Fix pi container repo mount and npm update permissions

Problem

After implementing configurable tool container home directories, new pi-agent containers still bind-mount the git repository at /workspace instead of under /home/user/{repo_name}. In addition, users cannot run npm update -g @earendil-works/pi-coding-agent inside the container because the global npm prefix (/usr/lib/node_modules) is owned by root.

Root cause

  1. The built-in pi-agent manifest in tool_definition_manifests still declares an explicit repo mount with "target": "/workspace" and "working_dir": "/workspace". This masks the generated /workspace → /home/user/{repo} compatibility symlink.
  2. manifest_compiler.py does not substitute the instance-specific {{WORKSPACE_NAME}} placeholder in explicit mount targets, and instance_service.py does not pass WORKSPACE_NAME/REPO_NAME to compile_compose for manifest-based tools.
  3. The generated entrypoint hardcodes the literal string {{WORKSPACE_NAME}} as the symlink target.
  4. npm_global packages are installed with RUN npm install -g ... as root into the system npm prefix, so the non-root container user cannot update them.
  5. Once the repo mount moves out of /workspace, the generated /workspace compatibility symlink is created in the image as root. The non-root entrypoint cannot replace it (write permission is required on /), so container startup fails.

Fix

  1. Add an Alembic data migration that updates the built-in pi-agent manifest:
    • Change the repo mount target to ~/{{WORKSPACE_NAME}}.
    • Keep runtime.working_dir as /workspace (the compatibility symlink).
    • Update the startup script to chown the real mount path ($HOME/$WORKSPACE_NAME).
  2. Update manifest_compiler.py:
    • Substitute {{WORKSPACE_NAME}} in mount targets in compile_compose.
    • Pass WORKSPACE_NAME as a container environment variable.
    • Generate the entrypoint symlink from the runtime WORKSPACE_NAME environment variable.
    • Install npm_global packages into a user-writable prefix ({home_dir}/.npm-global) and add it to PATH.
    • Use sudo or root to create the /workspace compatibility symlink, because / is owned by root and the non-root entrypoint cannot replace a root-owned symlink.
  3. Update instance_service.py to pass REPO_NAME and WORKSPACE_NAME into manifest compilation.
  4. Update unit tests for the new behavior.

Affected files

  • apps/api/alembic/versions/<new>_fix_pi_agent_home_directory_mount.py
  • apps/api/src/services/build/manifest_compiler.py
  • apps/api/src/services/tool/instance_service.py
  • apps/api/tests/unit/test_manifest_compiler.py

Verification

  • pytest apps/api/tests/unit/test_manifest_compiler.py
  • pytest apps/api/tests/unit/test_alembic_migrations.py
  • ruff, mypy, npm run typecheck, npm run lint