pub const NAME_THE_USER: &str = "passwd=${3:-/etc/passwd}; group=${4:-/etc/group}; \
grep -q \"^[^:]*:[^:]*:$2:\" \"$group\" || echo \"qcode-$2:x:$2:\" >> \"$group\"; \
grep -q \"^[^:]*:[^:]*:$1:\" \"$passwd\" || echo \"qcode-$1:x:$1:$2:QCode:/home/qcode:/bin/sh\" >> \"$passwd\"";Expand description
The shell that gives the person a name inside a container whose image has none for them, run as root in the container once it is up.
On docker the daemon runs the container as the ids QCode hands it (--user uid:gid), and an
image can only name the uid it was built with: USER at 1000. A person whose uid is another
one then has no name inside, and everything that looks one up fails on it — whoami cannot
answer, git commit refuses to write an author, Node’s os.userInfo() throws. The home
directory and the person’s own files are right; only the name is missing. Podman rootless maps
the person into the container’s user namespace and writes that entry itself, so nothing is
missing there and nothing here runs.
Run as sh -c <this> sh <uid> <gid>, with the ids as arguments rather than written into the
script, and the two files after them so that the same shell can be run against a copy of them:
passwd and group default to /etc/passwd and /etc/group.
Each line is looked for by the id in its own field and not by the name beside it, because the name is what this writes and the image may have written another one: so an image that already knows the uid is left as it is, and a container brought up twice is written once.
Nothing but sh, grep and echo is used, because every base QCode offers is somebody else’s
and none of the four carries the same set of programs.