Skip to content

fix: don't rm root-owned COPY temp files as non-root build user - #62

Merged
johnyaku merged 2 commits into
mainfrom
fix/pip-temp-cleanup-perms
Jun 17, 2026
Merged

johnyaku merged 2 commits into
mainfrom
fix/pip-temp-cleanup-perms

Conversation

@johnyaku

Copy link
Copy Markdown
Contributor

Problem

The Deploy-to-NCI run for #61 (merged) failed building absconda's own image:

185.9 No broken requirements found.        ← pip check passed
185.9 rm: cannot remove '/tmp/requirements.txt': Operation not permitted
ERROR: failed to build: ... exit code: 1

The conda+pip two-phase install itself worked. The failure was the cleanup step I added to the packed paths: the build runs as the non-root $MAMBA_USER, but COPY <<'ABSCONDA_PIP' /tmp/requirements.txt creates the file owned by root. In sticky /tmp, a non-owner can't delete it, so rm -f /tmp/requirements.txt failed and broke the && chain.

(The conda_on_base path runs as root, so its rm is fine — and that path isn't what CI builds.)

Fix

Drop the rm -f /tmp/requirements.txt /tmp/conda.constraints.txt line in builder_stage.j2 and single_stage.j2:

conda_on_base.j2 keeps its cleanup (runs as root, permitted).

Testing

  • pytest tests/test_templates.py: 9 passed; full suite green. ruff clean.
  • Re-rendered the multi-stage-with-pip Dockerfile and confirmed the && chain is intact (… pip check && conda-pack && …) with no rm of the COPY'd file.

Follow-up to #61. Merging this re-triggers Deploy-to-NCI, which should now build cleanly.

🤖 Generated with Claude Code

johnyaku and others added 2 commits June 18, 2026 09:45
The builder/single-stage paths run as $MAMBA_USER, but COPY creates
/tmp/requirements.txt owned by root. In sticky /tmp a non-owner can't
delete it, so `rm -f /tmp/requirements.txt` failed with "Operation not
permitted" and broke the build (CI #61).

Drop the cleanup in these two paths: the builder stage is discarded
(multi-stage), and single-stage already leaves /tmp/env.yaml behind, so
this is consistent and the leftover is a harmless few-KB text file. The
conda_on_base path runs as root and keeps its cleanup.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@johnyaku
johnyaku merged commit 96ea6aa into main Jun 17, 2026
9 checks passed
@johnyaku
johnyaku deleted the fix/pip-temp-cleanup-perms branch June 17, 2026 23:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant