Respect USER directive from OCI image config
CI / build (pull_request) Successful in 13s

Add support for the Dockerfile USER directive so that the container's
CMD/ENTRYPOINT runs as the configured user instead of root.

Changes:
- inject.rs: Add user field to Config struct, write /slim/user at
  build time
- build.rs: Pass config.user through to inject()
- slim-init.sh: Read /slim/user and drop privileges via su before
  executing the command. Numeric uids are resolved to usernames via
  /etc/passwd (BusyBox su does not accept numeric args). When dropping
  privileges, run as a child (not exec) so PID 1 stays root and can
  poweroff after the command exits.
- test.sh: Add test_user verifying build-time CMD and --cmd override
  both run as the configured user

Closes #7
This commit is contained in:
2026-09-10 00:00:42 +02:00
parent 5960cfe430
commit de59e84d73
4 changed files with 89 additions and 5 deletions
+35
View File
@@ -103,6 +103,39 @@ EOF
rm -rf "$work"
}
test_user() {
echo "=== Testing USER directive ==="
work="$(mktemp -d)"
img="slim-test-user"
cat > "$work/Containerfile" <<'EOF'
FROM alpine:latest
RUN adduser -D -u 1500 testuser
USER testuser
CMD ["/bin/sh", "-c", "echo USER_BUILD_OK:$(id -u):$(whoami); poweroff -f"]
EOF
echo "-- Building container image with USER directive..."
if ! podman build --network=none -t "$img" -f "$work/Containerfile" >/dev/null 2>&1; then
report fail "USER directive (podman build failed)"
rm -rf "$work"
return
fi
echo "-- Test 1: build-time CMD runs as USER"
"$SLIM_BIN" build qcow2 "$img" >/dev/null 2>&1
output=$(timeout "$TIMEOUT" "$SLIM_BIN" run "$img" 2>&1 || true)
check_output "$output" "USER_BUILD_OK:1500:testuser" "USER build-time CMD runs as testuser"
echo "-- Test 2: run --cmd override runs as USER"
output=$(timeout "$TIMEOUT" "$SLIM_BIN" run "$img" --cmd 'echo USER_RUN_OK:$(id -u):$(whoami); poweroff -f' 2>&1 || true)
check_output "$output" "USER_RUN_OK:1500:testuser" "USER run --cmd override runs as testuser"
cleanup "$img" "$img"
rm -rf "$work"
}
test_service() {
echo "=== Testing nextcloud service ==="
@@ -171,6 +204,8 @@ cargo build 2>&1
test_distro "alpine" "alpine:latest" ""
test_distro "archlinux" "archlinux:latest" "RUN pacman -Sy --noconfirm iproute2 wget; pacman -Sc --noconfirm"
test_user
test_service
echo ""