Repository navigation
fix(rtk): init the hook without /mnt/claude in ralphex-fe; close stdin at all rtk init sites - #168
Merged
Merged
Conversation
The rtk init block sat inside the `if [ -d /mnt/claude ]` guard, so a standalone container (no host ~/.claude mount) never got the PreToolUse rewrite hook and rtk stayed inert, silently. Hoist `mkdir -p /home/app/.claude` (rtk init -g fails without it), the `chown -R app:app` and the rtk init out of the guard; only the copying from /mnt/claude and the Playwright MCP patch stay behind it. Local additions are fenced with "Local:" banners, and the header no longer claims the file is copied as-is from umputun/ralphex. Fixes #128
A devcontainer postCreateCommand runs under a pseudo-TTY, so rtk's is_terminal() check passes and its telemetry consent prompt can block. RTK_TELEMETRY_DISABLED=1 opts out and `timeout 10` kills a hang, but a fired timeout is swallowed by `|| true` and leaves rtk silently unconfigured. Redirecting stdin from /dev/null makes the prompt unreachable instead. Applied to .devcontainer/init-plugins.sh, claude-code's init-plugins.sh and ralphex-fe/init-docker.sh. The env var and timeout stay; the adjacent comments now describe all three defences in three lines. Fixes #130
The previous commit made chown -R /home/app/.claude unconditional. That would also rewrite the owner of anything bind-mounted into the directory, e.g. a host .credentials.json, which newer ralphex wrappers mount. Restore chown -R to the guard, where it only touches copies this script made, and chown just the directory itself unconditionally. rtk init runs as app via gosu, so the files it creates are already app-owned.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Makes the rtk rewrite hook initialize in
ralphex-feeven without the host~/.claudemount, and adds< /dev/nullto all threertk initcall sites.Why
ralphex-fe/init-docker.shthertk initsat insideif [ -d /mnt/claude ]. A standalone container, with no host mount, never got a PreToolUse hook, and nothing reported it. rtk was installed but did nothing.RTK_TELEMETRY_DISABLED=1and atimeout 10that kills the hang. Since every call site ends in|| true, a timeout would leave rtk unconfigured with no signal. Closing stdin prevents the hang in the first place.Changes
ralphex-fe/init-docker.sh:mkdir -p /home/app/.claudeplus a non-recursivechown app:appon that directory, and the rtk init, now always run./mnt/claude, the Playwright MCP patch and the recursivechown -Rstay inside the guard, where they were.Local: … (#128)banners, set apart from the body copied from upstream..devcontainer/init-plugins.sh,claude-code/.devcontainer/init-plugins.sh,ralphex-fe/init-docker.sh:rtk init … < /dev/null, keeping bothRTK_TELEMETRY_DISABLED=1andtimeout 10. The rationale comments are trimmed to three lines.Notes
chown -Routside the guard would also rewrite the owner of anything bind-mounted into~/.claude, e.g. a host.credentials.json, which newer ralphex wrappers mount. That was the branch's second version and was caught in review; the third commit narrows it. rtk runs asappviagosu, so the files it creates areapp-owned without it.init.sh→/srv/init.shentrypoint path, run inclaude-code:latest(dash, rtk 0.49.0 = ralphex-fe's pin) with anappuser and agosushim:/home/app/.claudedoesn't exist (ralphex-fe: rtk is never initialized when the container runs without /mnt/claude #128 reproduced)settings.jsonhas the PreToolUse hookrtk hook claude, and everything isapp:app/mnt/claude:ro: the copiedsettings.jsonkeeps its keys and gets the hook merged in, and the copies areapp:app/home/app/.claude/.credentials.json: that file staysroot:rootdocker run -t, pseudo-TTY, rtk 0.49.0):rtk initis killed bytimeoutafter 10.1 s (exit 124).~/.claudevolume is idempotent and keeps existing hooks.shellcheckis clean on all three scripts.docker buildof ralphex-fe (the dev host's Docker disk was full), so the realgosu/dumb-initweren't exercised. CI builds and verifies both images.init-docker.shis an old snapshot of upstream, which has since changed a lot (seed_claude_home, bind-mounted credentials).ralphex-fe/README.mdlists RTK0.43.0, but the Dockerfile pins0.49.0(also noted in docs: normalize per-image README headings and shared sections #164).Fixes #128
Fixes #130