fe82a248ec
- Add Alembic migration to update built-in pi-agent manifest:
* repo mount target from /workspace to ~/{{WORKSPACE_NAME}}
* keep /workspace as compatibility symlink via working_dir
* update startup chown target to $HOME/$WORKSPACE_NAME
- Pass REPO_NAME and WORKSPACE_NAME to compile_compose from instance_service
- Substitute {{WORKSPACE_NAME}} in manifest mount targets and expose it as
a container env var so the entrypoint can create the /workspace symlink
- Generate entrypoint workspace symlink from runtime WORKSPACE_NAME env var
- Install npm_global packages into {home_dir}/.npm-global with PATH so the
non-root container user can update global packages
- Update manifest compiler unit tests for the new behavior
Quality gates:
- pytest tests/unit: 207 passed
- ruff: clean on changed files
- mypy: clean on changed files
- alembic heads: single head
2.4 KiB
2.4 KiB
Fix pi container repo mount and npm update permissions
Problem
After implementing configurable tool container home directories, new pi-agent containers still bind-mount the git repository at /workspace instead of under /home/user/{repo_name}. In addition, users cannot run npm update -g @earendil-works/pi-coding-agent inside the container because the global npm prefix (/usr/lib/node_modules) is owned by root.
Root cause
- The built-in
pi-agentmanifest intool_definition_manifestsstill declares an explicit repo mount with"target": "/workspace"and"working_dir": "/workspace". This masks the generated/workspace → /home/user/{repo}compatibility symlink. manifest_compiler.pydoes not substitute the instance-specific{{WORKSPACE_NAME}}placeholder in explicit mount targets, andinstance_service.pydoes not passWORKSPACE_NAME/REPO_NAMEtocompile_composefor manifest-based tools.- The generated entrypoint hardcodes the literal string
{{WORKSPACE_NAME}}as the symlink target. npm_globalpackages are installed withRUN npm install -g ...as root into the system npm prefix, so the non-root container user cannot update them.
Fix
- Add an Alembic data migration that updates the built-in
pi-agentmanifest:- Change the repo mount target to
~/{{WORKSPACE_NAME}}. - Keep
runtime.working_diras/workspace(the compatibility symlink). - Update the startup script to chown the real mount path (
$HOME/$WORKSPACE_NAME).
- Change the repo mount target to
- Update
manifest_compiler.py:- Substitute
{{WORKSPACE_NAME}}in mount targets incompile_compose. - Pass
WORKSPACE_NAMEas a container environment variable. - Generate the entrypoint symlink from the runtime
WORKSPACE_NAMEenvironment variable. - Install
npm_globalpackages into a user-writable prefix ({home_dir}/.npm-global) and add it toPATH.
- Substitute
- Update
instance_service.pyto passREPO_NAMEandWORKSPACE_NAMEinto manifest compilation. - Update unit tests for the new behavior.
Affected files
apps/api/alembic/versions/<new>_fix_pi_agent_home_directory_mount.pyapps/api/src/services/build/manifest_compiler.pyapps/api/src/services/tool/instance_service.pyapps/api/tests/unit/test_manifest_compiler.py
Verification
pytest apps/api/tests/unit/test_manifest_compiler.pypytest apps/api/tests/unit/test_alembic_migrations.pyruff,mypy,npm run typecheck,npm run lint