Commit 02dbf69
fix(docker): expand ~ and $VAR in extra_mounts destinations (#128)
* fix(docker): expand ~ and $VAR in extra_mounts destinations
The source side of an extra_mounts spec is normalized with
expandvars(expanduser(...)) so authors can write portable specs; the
destination was only checked for a leading "/" and never expanded.
That asymmetry makes one common mount impossible to write portably.
env_passthrough forwards HOME with the HOST value on purpose, so any
container-side path that must line up with $HOME -- $HOME/.uipath for the
uip CLI's saved login state, for instance -- has a different literal value
on every host. The only way to express it was to hardcode one host's home
directory, which then mounts to the wrong place everywhere else. A login
state the CLI cannot see fails tasks as a capability problem rather than a
config one, so the misconfiguration is close to invisible: it cost 26% of
the rows in an ad-hoc Maestro run before it was spotted.
Expand the destination the same way, before the absolute-path check, so
`~/.uipath:$HOME/.uipath:rw` resolves. Two details worth keeping:
- expandvars leaves an unset variable verbatim, so a typo'd name still
fails the absolute-path check. The message now shows the raw and the
expanded form, otherwise it reads as a puzzle.
- the framework-owned-mount check runs on the expanded destination, since
a variable could itself expand to /work or / and the raw form would sail
past the gate.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* docs(docker): trim the extra_mounts destination comments to scope
The added docstring and test docstrings justified destination expansion with
`$HOME`/`.uipath`, which is not a case this serves: skills experiments mount
login state at a literal destination. Restate it against the one real
consumer, a container path that has to match a host-valued var.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix(docker): reject expansions that inject a ':' into a mount path
Two problems.
`ruff format` wanted the destination error on one line, which failed the
Quality Gate and the Windows Smoke Test.
More importantly, a variable whose value carries a ':' added fields to the
spec rebuilt at the bottom of the validator. `SNEAKY=/mnt/x:rw` in
`$real:$SNEAKY:ro` produced `/real:/mnt/x:rw:ro`, moving the destination and
widening a declared read-only mount. Guard both sides after expansion,
excluding the Windows drive prefix whose colon is legitimate and already
split off. Two tests cover it.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>1 parent f6d99ff commit 02dbf69
2 files changed
Lines changed: 55 additions & 8 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
290 | 290 | | |
291 | 291 | | |
292 | 292 | | |
293 | | - | |
294 | | - | |
295 | | - | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
296 | 296 | | |
297 | 297 | | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
298 | 301 | | |
299 | 302 | | |
300 | 303 | | |
| |||
312 | 315 | | |
313 | 316 | | |
314 | 317 | | |
315 | | - | |
| 318 | + | |
316 | 319 | | |
317 | 320 | | |
318 | 321 | | |
319 | 322 | | |
320 | 323 | | |
321 | 324 | | |
322 | | - | |
| 325 | + | |
323 | 326 | | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
324 | 335 | | |
325 | | - | |
| 336 | + | |
| 337 | + | |
| 338 | + | |
326 | 339 | | |
327 | 340 | | |
328 | | - | |
329 | | - | |
330 | 341 | | |
331 | 342 | | |
332 | 343 | | |
333 | 344 | | |
334 | 345 | | |
| 346 | + | |
335 | 347 | | |
336 | 348 | | |
337 | 349 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
108 | 108 | | |
109 | 109 | | |
110 | 110 | | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
111 | 146 | | |
112 | 147 | | |
113 | 148 | | |
| |||
0 commit comments