[BUG] Webcam setup is skipped on every start after the first when /dev persists and mknod is not permitted
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 88/100
Direzione di ricerca
Inizia nel blocco webcam di init-selkies-config e confronta il controllo dell’esistenza di /dev/video0 con il blocco gamepad sopra di esso. Riproduci il problema con il comando docker run fornito usando --cap-drop=MKNOD, quindi ispeziona /run/s6/container_environment/ tra un avvio e l’altro per LD_PRELOAD e SELKIES_WEBCAM_ENABLED. Il lavoro è concluso quando la configurazione della webcam viene eseguita in un riavvio con un file regolare residuo, preservando il comportamento per un dispositivo reale.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Is there an existing issue for this?
- I have searched the existing issues
Current Behavior
Hello, and thank you for this image. We build a small application image on top of it and found something in the webcam setup that may affect others who run without CAP_MKNOD.
In init-selkies-config, the webcam block runs only when /dev/video0 does not exist:
if [[ -z ${NO_WEBCAM+x} ]] && [[ ! -e /dev/video0 ]] && { mknod /dev/video0 c 81 0 2>/dev/null || touch /dev/video0 2>/dev/null; }; then
Where mknod is not permitted, touch leaves an empty regular file. If the container's /dev survives a restart of the init, the file is still there on the next start, the ! -e test is false and the whole block is skipped. SELKIES_WEBCAM_ENABLED is not set, the sidebar toggle is not shown and the interposer is not added to LD_PRELOAD. The webcam works on the first start and not on any later one.
The gamepad block just above does not have this problem, because it has no existence test and touch succeeds on a file that is already there.
We saw it on a host that runs the image inside a long-lived LXC container and restarts only the service inside it, so /dev (a tmpfs) outlives the restart.
Expected Behavior
The webcam is set up on every start, as the gamepad devices are.
A possible fix: dropping the [[ ! -e /dev/video0 ]] test would make the block behave like the gamepad one, since touch is harmless on an existing file. If the test is there to protect a real device passed in from the host, testing for a character device instead ([[ ! -c /dev/video0 ]]) would keep that and still recover from a leftover file.
Steps To Reproduce
- Start the image without
CAP_MKNODand with a regular file already at/dev/video0, which is what a second start looks like on such a host (command below). - Look at
/run/s6/container_environment/:LD_PRELOADandSELKIES_WEBCAM_ENABLEDare absent. - Repeat without the
touch: both are set.
Environment
- OS: Debian based host, image run inside an LXC container
- How docker service was installed: reproduced with stock Docker on a desktop
CPU architecture
x86-64
Docker creation
docker run --rm --cap-drop=MKNOD \
--entrypoint sh ghcr.io/linuxserver/baseimage-selkies:dev-5e1478e9-ls23 \
-c 'touch /dev/video0; exec /init'
The same line is on master and ubunturesolute today.
Container logs
Nothing is logged for this: the block is skipped silently. State after start:
$ ls -la /dev/video0
-rwxrwxrwx 1 root root 0 ... /dev/video0
$ cat /run/s6/container_environment/LD_PRELOAD
cat: /run/s6/container_environment/LD_PRELOAD: No such file or directory
$ cat /run/s6/container_environment/SELKIES_WEBCAM_ENABLED
cat: /run/s6/container_environment/SELKIES_WEBCAM_ENABLED: No such file or directory
We work around it by removing a regular-file /dev/video0 before /init, so there is no urgency on our side, and we are glad to test a change. Thank you for your work on this.
- Lingua principale
- Shell
- Stelle
- 229
- Fork
- 33
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di linuxserver/docker-baseimage-selkies
-
[FEAT] Downloadordner wählenApertaenhancement
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
linuxserver/docker-baseimage-selkies#192 · 2 commenti ·
Tutte le issue di linuxserver/docker-baseimage-selkies
Issue simili
-
Missing icon: BudsLinkAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
mattpocock/skills#1174 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
pnpm/pnpm#16635 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
documentation good first issue hacktoberfest
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
-
area/tests theme/ci-dx
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
I maintainer di solito rispondono entro 1 giorno