Skip to content

fix(containers): run tauri image as non-root - #5

Draft
seonghobae wants to merge 3 commits into
stats-server-nonrootfrom
tauri-nonroot
Draft

seonghobae wants to merge 3 commits into
stats-server-nonrootfrom
tauri-nonroot

Conversation

@seonghobae

@seonghobae seonghobae commented Oct 1, 2026 •

Copy link
Copy Markdown

Root cause

OpenCode PR #2 exact-head Security Scan run 36848110099, job 110323068088, reports Trivy DS-0002 for packages/containers/tauri-linux/Dockerfile. The independently published Tauri Linux build image inherited root and never selected a bounded runtime identity. Its inherited Cargo and Bun cache locations also assumed root-writable toolchain prefixes, so adding only a final USER would trade the scanner finding for build-time permission failures.

The first regression introduced at exact head e04a008e21e46b01fe49d5d583a76d460f5ba4a7 used raw substring checks. A fixture containing the required strings only in comments and a discarded build stage still passed that oracle, so it could not prove the final runtime stage owned the identity.

Repair

  • exact parent / stacked base: OpenCode fix(stats): run server image as non-root #4 head b65227ac6c3c4bfa830ad1b7964b9d8807104e21
  • exact head: 699f1408dae65120f5b88caa77359dff1c22d699
  • exact tree: d87cc9ae53e8258b0ab52bdad97a2a2c575863ea
  • runtime repair commit: 0606bcc58384a4bb92192e5d4b785afefe428dec
  • oracle repair commit: 699f1408dae65120f5b88caa77359dff1c22d699
  • create dedicated tauri UID/GID 10001 with home /home/tauri
  • keep Cargo and Bun package caches under that writable home without recursively changing inherited toolchain ownership
  • select USER tauri:tauri as the final production instruction
  • normalize Dockerfile instructions and validate account RUN, cache ENV, and final USER only inside the final stage
  • retain the comment/dead-stage bypass as an executable regression
  • bind the Gap, RCA, RED/GREEN evidence, acceptance gates, and four residual image owners in doctoring/CHANGELOG/baseline

Executable evidence

  • initial runtime RED on fix(stats): run server image as non-root #4 exact head: runtime identity and writable-cache contracts failed
  • oracle RED at e04a008…: inert comment/dead-stage fixture was accepted; 2 pass / 1 fail
  • oracle GREEN at 699f140… with Bun 1.3.14: 3 pass / 0 fail / 4 assertions
  • whitespace verification: clean

No local Docker/Podman runtime is available, so image-build and scanner success are not claimed.

Fresh hosted state

  • exact-head test run 36887913082: QUEUED
  • CodeRabbit commit status: SUCCESS
  • review threads: 0
  • qualifying approvals: 0
  • Security/SAST/CodeQL: not materialized on this Draft stacked head; no acceptance is claimed

Fresh exact-head build, Trivy/Semgrep, full product Checks, resolved review threads, and qualifying independent review remain required before ordinary merge.

Stack and status

This is intentionally Draft / Proposed / merge HOLD on #4. It must not merge before its base and exact-head gates are acceptable. The base, bun-node, publish, and rust images remain separate verified Gap work; this PR does not suppress or claim them.

No Force Push, destructive rebase, bypass, manual approval synthesis, or predecessor closure was used.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

This PR doesn't fully meet our contributing guidelines and PR template.

What needs to be fixed:

  • PR description is missing required template sections. Please use the PR template.

Please edit this PR description to address the above within 2 hours, or it will be automatically closed.

If you believe this was flagged incorrectly, please let a maintainer know.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Thanks for your contribution!

This PR doesn't have a linked issue. All PRs must reference an existing issue.

Please:

  1. Open an issue describing the bug/feature (if one doesn't exist)
  2. Add Fixes #<number> or Closes #<number> to this PR description

See CONTRIBUTING.md for details.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant