dabla opened a new pull request, #73606:
URL: https://github.com/apache/airflow/pull/73606

   Breeze already knows how to deal with rootless Docker (ADR 15): when the 
container's root maps back to the host user there is nothing to fix, so 
`scripts/in_container/run_fix_ownership.py` is meant to exit early when 
`DOCKER_IS_ROOTLESS` is set.
   
   The value never matched. `fix_ownership_using_docker()` formats the Python 
bool straight into the `-e` argument, so the container received 
`DOCKER_IS_ROOTLESS=True`, while the script only skips on the lowercase string 
`true`. The `VERBOSE` variable right above it is lowercased; this one was not. 
The `breeze shell` entry path is unaffected because `ShellParams._set_var` 
lowercases booleans.
   
   The consequence under rootless Docker (here: Docker Engine 29 rootless on 
WSL2) is the opposite of the intent. Inside the container every file owned by 
the host user looks root-owned, so the script chowns the whole mounted checkout 
to the mapped uid, which lands on a subordinate uid on the host (100999 for uid 
1000). Git then refuses the repository as dubiously owned, prek can no longer 
read the files, and a uv cache hardlinked into the checkout's `.venv` changes 
owner as well. This happens after every `breeze run` and therefore after every 
prek hook that goes through Breeze, such as `check-provider-yaml-valid`.
   
   Reproduction with the unmodified script in a scratch directory, with 
`HOST_USER_ID=1000` and a plain `python:3.12-slim` image:
   
   | `DOCKER_IS_ROOTLESS` | Owner afterwards |
   | --- | --- |
   | `True` | 100999 |
   | `true` | 1000 (skipped with the rootless message) |
   
   Changes:
   
   * Lowercase the flag in `fix_ownership_using_docker()`, matching `VERBOSE`.
   * Make the in-container script compare case-insensitively so another caller 
cannot reintroduce the mismatch.
   * Add a Breeze unit test asserting the rendered `-e` argument for both 
rootless states. It fails on the previous code.
   
   Checks executed: the new test in 
`dev/breeze/tests/test_docker_command_utils.py` (2 passed, both fail without 
the fix), the reproduction above against the patched script (`True`, `true` and 
`false` now behave as intended), and `prek run --files` on the three changed 
files (all hooks passed, including mypy).
   
   ---
   
   ##### Was generative AI tooling used to co-author this PR?
   
   - [X] Yes (please specify the tool below)
   
   Generated-by: Claude Code (Fable 5.1) following [the 
guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions)
   
   ---
   
   * Read the **[Pull Request 
Guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#pull-request-guidelines)**
 for more information. Note: commit author/co-author name and email in commits 
become permanently public when merged.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to