Repository navigation
fix(claude-code): create /etc/claude-code as root so managed-settings is readable - #101
Merged
Merged
Conversation
… is readable BuildKit applies COPY --chmod to any parent directories it auto-creates, so "COPY --chmod=0644 managed-settings.json /etc/claude-code/managed-settings.json" landed the file inside a drw-r--r-- directory — no execute bit, not traversable by anyone in the container. The node user could not read the file even though the file mode itself was correct, and jq in the CI verify step failed with "Could not open file ... Permission denied". Pre-create the directory explicitly as root before the COPY, and copy the file with --chown=root:root so it matches normal /etc/ ownership conventions. Also add a test -r precondition to the verify-command so future breakage of this kind surfaces with a clear "file unreadable" failure before jq sees it. Verified locally: built --target base from the modified Dockerfile, confirmed /etc/claude-code is now drwxr-xr-x and managed-settings.json is -rw-r--r-- readable as the node user, and the full verify-command exits 0 under the exact bash -c wrapping the CI matrix uses.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Pre-creates
/etc/claude-codeas root beforeCOPY-ingmanaged-settings.jsoninto it, and adds atest -rprecondition to the CI verify-command.Why
PR #100's image-rebuild run (25776401543) failed all four verify legs with:
Reproduced locally against the published image at digest
sha256:2b31ced4…:Mode
0644on a directory means readable but not traversable — the file inside is unreachable by any user, including root inside this container.Root cause: BuildKit applies
COPY --chmod=Nnot only to the file but to any parent directories it auto-creates. The previousCOPY --chmod=0644 managed-settings.json /etc/claude-code/managed-settings.jsoncreated/etc/claude-codewith mode0644(noxbit) as a side effect.The file mode itself was correct; the bug was relying on BuildKit to materialize the parent dir with a sane default.
Changes
claude-code/.devcontainer/Dockerfile— switch toUSER root,mkdir -p /etc/claude-code(inherits root's umask →0755),COPY --chown=root:root --chmod=0644 managed-settings.json …, then drop back toUSER node. Adds the file under standard/etc/ownership conventions..github/workflows/build-claude-code.yml— prefix the four verify-command rows withtest -r /etc/claude-code/managed-settings.jsonso the next time this directory perm class of bug appears, CI fails with an explicit "file not readable" before jq is invoked. Sameprintenv | grep -qxquote-free shape as the surrounding checks.Notes
--target basefrom the modified Dockerfile, confirmed/etc/claude-codeis nowdrwxr-xr-xandmanaged-settings.jsonis-rw-r--r--, ran the exact verify-command underbash -c "<value>"(matching the GHA matrix expansion) inside the container — exit 0.docker build --target <stage>+ in-container repro before push, not just a syntactic check of the diff.Test plan
hadolintclean on modified Dockerfile.actionlintclean on modified workflow./etc/claude-codemode0755, file mode0644, readable asnode.bash -c "<value>"exits 0 in the locally built image.Build claude-codepost-merge run on master — all four verify legs (default/sandbox × amd64/arm64) should pass.Recovers from #99 / #100. Closes the loop on #98.