Skip to content

fix(template): preserve filesystem lost+found during tmp wipe - #937

Closed
homelab-agent-bot[bot] wants to merge 1 commit into
mainfrom
fix/tmp-lost-found
Closed

homelab-agent-bot[bot] wants to merge 1 commit into
mainfrom
fix/tmp-lost-found

Conversation

@homelab-agent-bot

Copy link
Copy Markdown
Contributor

Summary

  • recognize a non-symlink, root-owned /tmp/lost+found as a filesystem-created structural directory
  • preserve only that entry while the unprivileged container entrypoint wipes all ordinary scratch data
  • document why the exception does not create unwiped user-controlled storage

Why

A fresh ephemeral filesystem can expose a protected lost+found directory. The workspace container runs unprivileged, so attempting to remove it marks the /tmp wipe as failed and causes the blocking agent startup script to fail even though no stale workspace data remains.

The entrypoint checks type and ownership instead of excluding the name unconditionally. A workspace user cannot create a root-owned entry, so a user-created lost+found is still removed.

Validation

  • git diff --check
  • bash -n templates/kubernetes/homelab-workspace/scripts/script-container-entrypoint.sh
  • shellcheck templates/kubernetes/homelab-workspace/scripts/script-container-entrypoint.sh
  • pre-commit run --files DESIGN.md templates/kubernetes/homelab-workspace/scripts/script-container-entrypoint.sh
  • commit header validated with the repository's local commitlint installation

@homelab-agent-bot
homelab-agent-bot Bot marked this pull request as draft September 17, 2026 02:51
@homelab-agent-bot
homelab-agent-bot Bot marked this pull request as ready for review September 17, 2026 02:54
@ppat ppat closed this Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant