Commit 8e8c03891a

8e8c03891a17798067a8da0a034725bf44ece8d0

parent: fe4290fab4

Verified · cmc

cmc <hello@cleberg.net> · 2026-07-15 16:13 UTC

fix: refuse to start when the cache directory is not writable

An unwritable cache directory degraded silently: media still served, because
the download succeeds before the cache write is attempted, so the only symptom
was one "permission denied" line per request and a cache that never filled.
Every request re-fetched from the CDN.

Probe the directory at startup and exit with the uid and the chown that fixes
it. The container image runs as uid 10000, which is the usual cause with a
bind-mounted cache, so say so in the message and in both compose examples.

Layout: unified · split

SETUP.md +4 −1
@@ -12,7 +12,10 @@ Time units:
12* `uri` — Instance URI. Example: `"uri":"/art/"` -> https://skunky.ebloid.ru/art/ 12* `uri` — Instance URI. Example: `"uri":"/art/"` -> https://skunky.ebloid.ru/art/
13* `cache` — Caching system; default is off. 13* `cache` — Caching system; default is off.
14 * `enabled` — Caching system state, requires boolean value 14 * `enabled` — Caching system state, requires boolean value
15 * `path` — Path to cache directory, requires absolute filesystem path 15 * `path` — Path to cache directory. It must be writable by the user SkunkyArt
16 runs as, and SkunkyArt refuses to start if it is not. The container image
17 runs as uid 10000, so a bind-mounted cache needs
18 `sudo chown -R 10000:10000 <dir>` on the host.
16 * `lifetime` — Cached file life time, requires numeric value, followed by multiplicative suffix (see Time Units for details) 19 * `lifetime` — Cached file life time, requires numeric value, followed by multiplicative suffix (see Time Units for details)
17 * `max-size` — Maximum file size in megabytes 20 * `max-size` — Maximum file size in megabytes
18 * `update-interval` — Automatic rotation interval 21 * `update-interval` — Automatic rotation interval
app/config.go +28 −1
@@ -58,9 +58,28 @@ var CFG = config{
58 58
59var lifetimeParsed int64 59var lifetimeParsed int64
60 60
61// checkCacheWritable creates the cache directory if it is missing and confirms
62// this process can actually write into it, returning the error that a real cache
63// write would hit.
64//
65// An unwritable cache directory is otherwise a silent cliff: every media request
66// still succeeds by re-downloading from the CDN, so the only symptom is one
67// "permission denied" line per request and a cache that never fills.
68func checkCacheWritable(path string) error {
69 if err := os.MkdirAll(path, 0700); err != nil {
70 return err
71 }
72 probe := path + "/.skunkyart-write-probe"
73 if err := os.WriteFile(probe, nil, 0600); err != nil {
74 return err
75 }
76 return os.Remove(probe)
77}
78
61// ExecuteConfig loads the config file into CFG, validates it, and starts the 79// ExecuteConfig loads the config file into CFG, validates it, and starts the
62// cache rotation loop if caching is on. It exits the process on a config that 80// cache rotation loop if caching is on. It exits the process on a config that
63// cannot be read or that asks for caching without proxying. 81// cannot be read, that asks for caching without proxying, or that points caching
82// at a directory this process cannot write.
64func ExecuteConfig() { 83func ExecuteConfig() {
65 if CFG.cfg != "" { 84 if CFG.cfg != "" {
66 f, err := os.ReadFile(CFG.cfg) 85 f, err := os.ReadFile(CFG.cfg)
@@ -71,6 +90,14 @@ func ExecuteConfig() {
71 } 90 }
72 91
73 if CFG.Cache.Enabled { 92 if CFG.Cache.Enabled {
93 if err := checkCacheWritable(CFG.Cache.Path); err != nil {
94 exit("Cache directory is not writable by this process (uid "+
95 strconv.Itoa(os.Getuid())+"): "+err.Error()+
96 "\nGrant that uid write access to the directory, or set cache.enabled to false."+
97 "\nThe official container image runs as uid 10000, so a bind-mounted cache needs:"+
98 "\n chown -R 10000:10000 <cache dir on the host>", 1)
99 }
100
74 if CFG.Cache.Lifetime != "" { 101 if CFG.Cache.Lifetime != "" {
75 var duration int64 102 var duration int64
76 day := 24 * time.Hour.Milliseconds() 103 day := 24 * time.Hour.Milliseconds()
compose.example.yaml +4 −1
@@ -14,4 +14,7 @@ services:
14 - no-new-privileges:true 14 - no-new-privileges:true
15 volumes: 15 volumes:
16 - ./config.json:/config.json:ro 16 - ./config.json:/config.json:ro
17 - ./cache:/cache # Ensure cache folder has a 10000:10000 ownership. 17 # The image runs as uid 10000, so the host cache dir must be writable by it:
18 # mkdir -p cache && sudo chown -R 10000:10000 cache
19 # Without this the container exits at startup telling you the same thing.
20 - ./cache:/cache
compose.vpn_example.yml +3 −1
@@ -59,7 +59,9 @@ services:
59 - no-new-privileges:true 59 - no-new-privileges:true
60 volumes: 60 volumes:
61 - ./config.json:/config.json:ro 61 - ./config.json:/config.json:ro
62 - ./cache:/cache # ensure this dir is owned 10000:10000 62 # The image runs as uid 10000, so the host cache dir must be writable by it:
63 # mkdir -p cache && sudo chown -R 10000:10000 cache
64 - ./cache:/cache
63 environment: 65 environment:
64 # Empty by default = direct. Set SKUNKY_PROXY in .env to route via the VPN. 66 # Empty by default = direct. Set SKUNKY_PROXY in .env to route via the VPN.
65 - HTTPS_PROXY=${SKUNKY_PROXY:-} 67 - HTTPS_PROXY=${SKUNKY_PROXY:-}