Skip to content

containers.run() runs as root instead of local user #78

Description

@richardhboyd

When trying to follow the readme. This happened at the cfn submit --dry-run step.

=== Unhandled exception ===
Please report this issue to the team.
Issue tracker: https://github.com/aws-cloudformation/aws-cloudformation-rpdk/issues
Please include the log file 'rpdk.log'

here's a link to the gist

Activity

  1. rjlohan commented on Feb 21, 2020

    @rjlohan

    Error log shows PermissionError: [Errno 13] Permission denied: '/home/ec2-user/environment/resourceProvider/build/richard_pokedex_database'

    Looks like a local configuration issue on your box. We can keep this issue open to surface errors like this more usefully in the CLI output though.

  2. changed the title [-]Please report this issue to the team.[/-] [+]Better surface local errors; Error log shows `PermissionError: [Errno 13] Permission denied: ...`[/+] on Feb 21, 2020
  3. richardhboyd commented on Feb 21, 2020

    @richardhboyd
    ContributorAuthor

    Not sure where to begin debugging that. That folder is owned by the user I was using to run the command. The cfn submit doesn't seem to be using the venv environment that I had active when running the command.

    This is being run on a fresh Cloud9 instance.

    Also tried to do it with Python3.6 and got the same error.

  4. rjlohan commented on Feb 21, 2020

    @rjlohan

    OK let us take a look at that further. Looks like there's a few other errors in your rpdk.log too, might be something earlier in the chain that's not right (like having the Python plugin available?)

  5. johnttompkins commented on Feb 21, 2020

    @johnttompkins
    Contributor

    Transferred over to the python plugin repo since it looks plugin specific. Will take a look

  6. richardhboyd commented on Feb 21, 2020

    @richardhboyd
    ContributorAuthor

    I also don't appear to own the ./build directory. look like it's owned by root even though I'm running the cfn submit command as ec2-user

    I used the pip install git+https://github.com/aws-cloudformation/aws-cloudformation-rpdk-python-plugin.git#egg=cloudformation-cli-python-plugin command to install the Python plugin, but then appeared to also need to git clone the project and run package_lib.sh command to generate the zip, then copy it to the root of my project.

  7. richardhboyd commented on Feb 21, 2020

    @richardhboyd
    ContributorAuthor

    sudo ./env/bin/cfn submit --dry-run "works" but is far from ideal.

  8. richardhboyd commented on Feb 21, 2020

    @richardhboyd
    ContributorAuthor

    My completely uninformed detective skills have me convinced that the shutils.copyTree() is somehow either running as root (unlikely) or using the system Python (which was installed by the root user) and that's affecting the permissions of the copied artifacts.

  9. richardhboyd commented on Feb 22, 2020

    @richardhboyd
    ContributorAuthor

    New theory!! Setting use_container to false fixes the problem. New hypothesis is that docker is running as root so when it builds my Resource Provider it is doing it as root and then ec2-user doesn't have sufficient permission when we continue after the self._docker_build() command

  10. richardhboyd commented on Feb 22, 2020

    @richardhboyd
    ContributorAuthor

    Okay, I have literally no idea why/how this works but if you add "echo pwd &&", as the first string in the _make_pip_command() method then the build works.

    Inserting the command before this line

  11. changed the title [-]Better surface local errors; Error log shows `PermissionError: [Errno 13] Permission denied: ...`[/-] [+]containers.run() runs as root instead of local user[/+] on Feb 22, 2020
  12. richardhboyd commented on Feb 23, 2020

    @richardhboyd
    ContributorAuthor

    I just tried this in a fresh AmazonLinux2 image (plain, not a Cloud9 instance). I installed Python3.7 by building it from source as the root user, then updated the symlinks so python/pip point to python3.7/pip3.7.

    AMI: amzn-ami-hvm-2018.03.0.20200206.0-x86_64-gp2 (ami-079f731edfe27c29c)

    Here is the userdata for the instance

    yum update -y
    yum install jq git zlib libcurl -y
    yum install gcc openssl-devel bzip2-devel libffi-devel docker -y
    service docker start
    usermod -a -G docker ec2-user
    wget https://www.python.org/ftp/python/3.7.4/Python-3.7.4.tgz
    tar xzf Python-3.7.4.tgz
    cd Python-3.7.4
    ./configure --enable-optimizations
    make altinstall
    # Remove old symlinks
    rm -rf /etc/alternatives/pip
    rm -rf /etc/alternatives/python
    # make new symlinks
    ln -s /usr/local/bin/pip3.7 /etc/alternatives/pip
    ln -s /usr/local/bin/python3.7 /etc/alternatives/python

    Once the instance was up and running. cfn-cli was installed with these commands:

    mkdir ResourceProvider
    cd ResourceProvider/
    python -m venv env
    source env/bin/activate
    ./env/bin/pip install cloudformation-cli
    ./env/bin/pip install git+https://github.com/aws-cloudformation/aws-cloudformation-rpdk-python-plugin.git#egg=cloudformation-cli-python-plugin
    cd ../
    git clone https://github.com/aws-cloudformation/cloudformation-cli-python-plugin.git
    cd cloudformation-cli-python-plugin/
    ./package_lib.sh 
    cp cloudformation-cli-python-lib-0.0.1.tar.gz ../ResourceProvider/
    cd ../ResourceProvider/
    cfn init
    cfn submit --dry-run

    rpdk.log
    I'm convinced that this is a bug in the python plugin and not a Cloud9/AL2 AMI

  13. richardhboyd commented on Feb 25, 2020

    @richardhboyd
    ContributorAuthor

    fix merged

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions