Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion cron/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ RUN if [ -n "${HTTP_PROXY}" ]; then echo "Acquire::http::proxy \"${HTTP_PROXY}\"
RUN if [ -n "${HTTPS_PROXY}" ]; then echo "Acquire::https::proxy \"${HTTPS_PROXY}\";" >> /etc/apt/apt.conf; fi
RUN if [ -n "${http_proxy}" ]; then echo "Acquire::http::proxy \"${http_proxy}\";" >> /etc/apt/apt.conf; fi
RUN if [ -n "${https_proxy}" ]; then echo "Acquire::https::proxy \"${https_proxy}\";" >> /etc/apt/apt.conf; fi
RUN apt-get update && apt-get install -y --no-install-recommends cron && \
RUN apt-get update && apt-get install -y --no-install-recommends cron gosu && \
rm -r /var/lib/apt/lists/*
COPY entrypoint.sh /entrypoint.sh
ENTRYPOINT ["/entrypoint.sh"]
1 change: 1 addition & 0 deletions install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@ source install/check-memcached-backend.sh
source install/ensure-relay-credentials.sh
source install/generate-secret-key.sh
source install/build-docker-images.sh
source install/ensure-sentry-data-ownership.sh
source install/migrate-seaweedfs-kek.sh
source install/upgrade-postgres.sh
source install/bootstrap-s3-nodestore.sh
Expand Down
25 changes: 25 additions & 0 deletions install/ensure-sentry-data-ownership.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
echo "${_group}Ensuring sentry-data volume ownership ..."

# Sentry containers run as the non-root `sentry` user (uid 999). Older sentry
# images fixed /data ownership at every container start while running as root;
# do it once here instead. This uses python3 rather than shell tools so it keeps
# working on images without a shell.
$dcr --no-deps --user 0 --entrypoint python3 web -c '
import os

SENTRY_UID = 999


def fail(error):
raise error


os.makedirs("/data/files", exist_ok=True)
if any(os.stat(p).st_uid != SENTRY_UID for p in ("/data", "/data/files")):
for root, dirs, files in os.walk("/data", topdown=False, onerror=fail):
for path in (*(os.path.join(root, name) for name in dirs + files), root):
if os.lstat(path).st_uid != SENTRY_UID:
os.lchown(path, SENTRY_UID, -1)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ownership check skips nested files

Medium Severity

The install-time chown only walks /data when /data or /data/files themselves are not uid 999. Those two directories are the first paths updated, so an interrupted run, a volume whose root is already 999, or leftover root-owned trees such as custom-packages make the next ./install.sh skip the walk. Nested files then stay root-owned, and the non-root sentry process cannot write them. The old entrypoint repaired ! -user sentry files on every start; this path cannot recover.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 582885b. Configure here.

@oioki oioki Sep 29, 2026 •

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good bot. Now walks bottom-up so interrupted runs resume. Nested-files case matches the old entrypoint's guard, so leaving that.

'

echo "${_endgroup}"
11 changes: 11 additions & 0 deletions sentry/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,6 +1,10 @@
ARG SENTRY_IMAGE
FROM ${SENTRY_IMAGE}

# Customizations below need root. Newer sentry images default to the non-root
# `sentry` user, so switch explicitly and switch back at the end.
USER 0

RUN pip install https://github.com/getsentry/sentry-nodestore-s3/archive/main.zip

COPY . /usr/src/sentry
Expand All @@ -13,3 +17,10 @@ RUN if [ -s /usr/src/sentry/requirements.txt ]; then \
echo "sentry/requirements.txt is deprecated, use sentry/enhance-image.sh - see https://develop.sentry.dev/self-hosted/#enhance-sentry-image"; \
pip install -r /usr/src/sentry/requirements.txt; \
fi

# Let the non-root sentry user run update-ca-certificates (sentry/entrypoint.sh)
# for custom CAs mounted from ./certificates. It only needs to create symlinks
# and replace the bundle in this directory.
RUN chown sentry:sentry /etc/ssl/certs

USER sentry
Loading