Repository navigation
containers.run() runs as root instead of local user #78
Description
Activity
Error log shows
PermissionError: [Errno 13] Permission denied: '/home/ec2-user/environment/resourceProvider/build/richard_pokedex_database'Looks like a local configuration issue on your box. We can keep this issue open to surface errors like this more usefully in the CLI output though.
- changed the title
[-]Please report this issue to the team.[/-][+]Better surface local errors; Error log shows `PermissionError: [Errno 13] Permission denied: ...`[/+]on Feb 21, 2020 Not sure where to begin debugging that. That folder is owned by the user I was using to run the command. The
cfn submitdoesn't seem to be using the venv environment that I had active when running the command.This is being run on a fresh Cloud9 instance.
Also tried to do it with Python3.6 and got the same error.
OK let us take a look at that further. Looks like there's a few other errors in your
rpdk.logtoo, might be something earlier in the chain that's not right (like having the Python plugin available?)Transferred over to the python plugin repo since it looks plugin specific. Will take a look
I also don't appear to own the
./builddirectory. look like it's owned by root even though I'm running thecfn submitcommand as ec2-userI used the
pip install git+https://github.com/aws-cloudformation/aws-cloudformation-rpdk-python-plugin.git#egg=cloudformation-cli-python-plugincommand to install the Python plugin, but then appeared to also need togit clonethe project and runpackage_lib.shcommand to generate the zip, then copy it to the root of my project.sudo ./env/bin/cfn submit --dry-run"works" but is far from ideal.My completely uninformed detective skills have me convinced that the shutils.copyTree() is somehow either running as root (unlikely) or using the system Python (which was installed by the root user) and that's affecting the permissions of the copied artifacts.
New theory!! Setting use_container to false fixes the problem. New hypothesis is that docker is running as root so when it builds my Resource Provider it is doing it as root and then ec2-user doesn't have sufficient permission when we continue after the self._docker_build() command
Okay, I have literally no idea why/how this works but if you add
"echo pwd &&",as the first string in the _make_pip_command() method then the build works.Inserting the command before this line
- changed the title
[-]Better surface local errors; Error log shows `PermissionError: [Errno 13] Permission denied: ...`[/-][+]containers.run() runs as root instead of local user[/+]on Feb 22, 2020 I just tried this in a fresh AmazonLinux2 image (plain, not a Cloud9 instance). I installed Python3.7 by building it from source as the root user, then updated the symlinks so python/pip point to python3.7/pip3.7.
AMI: amzn-ami-hvm-2018.03.0.20200206.0-x86_64-gp2 (ami-079f731edfe27c29c)
Here is the userdata for the instance
yum update -y yum install jq git zlib libcurl -y yum install gcc openssl-devel bzip2-devel libffi-devel docker -y service docker start usermod -a -G docker ec2-user wget https://www.python.org/ftp/python/3.7.4/Python-3.7.4.tgz tar xzf Python-3.7.4.tgz cd Python-3.7.4 ./configure --enable-optimizations make altinstall # Remove old symlinks rm -rf /etc/alternatives/pip rm -rf /etc/alternatives/python # make new symlinks ln -s /usr/local/bin/pip3.7 /etc/alternatives/pip ln -s /usr/local/bin/python3.7 /etc/alternatives/python
Once the instance was up and running. cfn-cli was installed with these commands:
mkdir ResourceProvider cd ResourceProvider/ python -m venv env source env/bin/activate ./env/bin/pip install cloudformation-cli ./env/bin/pip install git+https://github.com/aws-cloudformation/aws-cloudformation-rpdk-python-plugin.git#egg=cloudformation-cli-python-plugin cd ../ git clone https://github.com/aws-cloudformation/cloudformation-cli-python-plugin.git cd cloudformation-cli-python-plugin/ ./package_lib.sh cp cloudformation-cli-python-lib-0.0.1.tar.gz ../ResourceProvider/ cd ../ResourceProvider/ cfn init cfn submit --dry-run
rpdk.log
I'm convinced that this is a bug in the python plugin and not a Cloud9/AL2 AMIfix merged
When trying to follow the readme. This happened at the
cfn submit --dry-runstep.here's a link to the gist