fix(containers): run tauri image as non-root - #5
seonghobae wants to merge 3 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
This PR doesn't fully meet our contributing guidelines and PR template. What needs to be fixed:
Please edit this PR description to address the above within 2 hours, or it will be automatically closed. If you believe this was flagged incorrectly, please let a maintainer know. |
|
Thanks for your contribution! This PR doesn't have a linked issue. All PRs must reference an existing issue. Please:
See CONTRIBUTING.md for details. |
Root cause
OpenCode PR #2 exact-head Security Scan run
36848110099, job110323068088, reports TrivyDS-0002forpackages/containers/tauri-linux/Dockerfile. The independently published Tauri Linux build image inherited root and never selected a bounded runtime identity. Its inherited Cargo and Bun cache locations also assumed root-writable toolchain prefixes, so adding only a finalUSERwould trade the scanner finding for build-time permission failures.The first regression introduced at exact head
e04a008e21e46b01fe49d5d583a76d460f5ba4a7used raw substring checks. A fixture containing the required strings only in comments and a discarded build stage still passed that oracle, so it could not prove the final runtime stage owned the identity.Repair
b65227ac6c3c4bfa830ad1b7964b9d8807104e21699f1408dae65120f5b88caa77359dff1c22d699d87cc9ae53e8258b0ab52bdad97a2a2c575863ea0606bcc58384a4bb92192e5d4b785afefe428dec699f1408dae65120f5b88caa77359dff1c22d699tauriUID/GID 10001 with home/home/tauriUSER tauri:taurias the final production instructionRUN, cacheENV, and finalUSERonly inside the final stageExecutable evidence
e04a008…: inert comment/dead-stage fixture was accepted;2 pass / 1 fail699f140…with Bun 1.3.14:3 pass / 0 fail / 4 assertionsNo local Docker/Podman runtime is available, so image-build and scanner success are not claimed.
Fresh hosted state
testrun36887913082: QUEUEDFresh exact-head build, Trivy/Semgrep, full product Checks, resolved review threads, and qualifying independent review remain required before ordinary merge.
Stack and status
This is intentionally Draft / Proposed / merge HOLD on #4. It must not merge before its base and exact-head gates are acceptable. The
base,bun-node,publish, andrustimages remain separate verified Gap work; this PR does not suppress or claim them.No Force Push, destructive rebase, bypass, manual approval synthesis, or predecessor closure was used.