(withdrawn) - #27
(withdrawn)#27yingerbucang wants to merge 1 commit into
Conversation
linuxserver.io images are designed to start as root and drop privileges internally via PUID/PGID env vars (s6-overlay). Forcing a compose 'user: UID:GID' on them makes s6 run as an unprivileged user that cannot fix permissions on root-owned dirs, and the container crash-loops: /run belongs to uid 0 instead of 1000 - fixing it s6-chmod: fatal: unable to change mode of /run: Operation not permitted s6-overlay-suexec: fatal: child failed with exit code 111 Reproduced on Ubuntu 24.04 + Docker 29.1.3 with jellyfin:10.11.10: container restart-loops and nothing listens on 8096. Removing the user: directive fixes it (PUID/PGID are still honored by s6, so file ownership is unchanged). Radarr/Sonarr/Prowlarr already work this way in this compose file; plex had the same latent bug.
|
ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe Plex and Jellyfin services no longer set Compose’s ChangesContainer startup configuration
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The change removes the startup override from both services while preserving their configured ownership settings; no merge-blocking risk remains. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change restores the images’ intended startup configuration without adding ports, mounts, or capabilities. Initial privileged execution now depends on the images correctly dropping application privileges. No vulnerability was established, but the exact images’ privilege-dropping and recovery behavior remains unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Withdrawing — please disregard. |
(withdrawn)