Files
hermes-agent/scripts/termux/assembly_permissions.sh
ethernet febb908bd1 fix(build): preserve toolchain state and Termux assembly ownership
Reuse a matching ARM64 Visual Studio environment instead of growing its paths on each initialization. Preserve Rust and Cargo homes before isolating bundle state. Hand the private Termux assembly directory to its container user and restore host ownership afterward.

Verified targeted tests, real ARM64 SDK/OpenSSL execution, Rust compilation, and container facts publication. Full release packages were not rebuilt. The Windows x64 source-build timeout and the unchanged Termux linkage fixture failure remain unresolved.
2026-09-12 02:05:48 -04:00

19 lines
844 B
Bash

#!/usr/bin/env bash
# Host-side ownership handoff for the disposable environment assembly mount.
prepare_assembly() {
ASSEMBLY="$(mktemp -d "$PAYLOAD_ABS/.environments-XXXXXX")"
# Docker would create the parent of the nested tool mounts as root:root.
# Pre-create it and hand off the private scratch tree to Termux's system uid.
mkdir "$ASSEMBLY/tools"
docker run --rm --user 0:0 --network none --entrypoint chown \
-v "$ASSEMBLY:/assembly" "$IMAGE" 1000:1000 /assembly /assembly/tools
}
restore_assembly_owner() {
# No input mounts are present here: never recurse through mounted tools/app.
# Bypass Termux's entrypoint, which otherwise drops root to uid 1000.
docker run --rm --user 0:0 --network none --entrypoint chown \
-v "$ASSEMBLY:/assembly" "$IMAGE" -R "$(id -u):$(id -g)" /assembly
}