fix(python/robomp): ensured omp run directory remained writable for all slots

- Added entrypoint setup for `/srv/agent-home/.omp/run` to enforce `omp` group ownership, group-write access, and setgid permissions so any sandbox slot can create or enter daemon state directories.
- Updated worker startup to skip generic home normalization on `.omp/run` and added a root-only run-dir preparation pass that reasserts `omp` ownership and writable, setgid permissions before launching subprocesses.
This commit is contained in:
can1357
2026-07-14 17:56:37 +02:00
parent 3047c27c33
commit 465f463ada
2 changed files with 47 additions and 0 deletions
+11
View File
@@ -69,6 +69,17 @@ chown -R root:root /srv/agent-home || true
find /srv/agent-home -type d -exec chmod 0755 {} +
find /srv/agent-home -type f -exec chmod 0644 {} +
# omp registers daemon project presence under ~/.omp/run at startup, nesting
# per-project dirs (daemons/<hash>/clients) that any slot user must be able to
# create and enter regardless of which slot first made them: setgid + group
# omp keeps the whole tree group-writable (entrypoint umask 0002 carries into
# slot processes, so new entries stay group-writable too).
mkdir -p /srv/agent-home/.omp/run
chgrp -R omp /srv/agent-home/.omp/run
chmod -R g+rwX /srv/agent-home/.omp/run
find /srv/agent-home/.omp/run -type d -exec chmod g+s {} +
chmod 2770 /srv/agent-home/.omp/run
touch /data/robomp.sqlite
chown root:root /data/robomp.sqlite
chmod 0600 /data/robomp.sqlite