Fix shared upload permissions for capability-restricted LTX backend
This commit is contained in:
@@ -27,6 +27,10 @@ outputs are mounted read-only. Only configured input/output roots are readable;
|
||||
traversal and symlinks escaping those roots are rejected. ffmpeg/ffprobe create
|
||||
thumbnails, dimensions and extracted frames on CPU; they are not inference runtimes.
|
||||
Network protocols are disabled for media inspection. HTTP Range supports seeking.
|
||||
Uploads, copied assets and thumbnails are mode 0640. Provision the writable input
|
||||
folder with a shared backend group and mode 2750 (setgid), so new files inherit
|
||||
that group. Both service identities must be able to traverse/read the shared
|
||||
folder; a root UID with dropped capabilities cannot bypass ordinary permissions.
|
||||
|
||||
Projects: initial preview retains the upstream browser-local project storage.
|
||||
Projects are specific to this browser/origin, not multiuser or cross-device synced.
|
||||
|
||||
@@ -7,7 +7,8 @@ The additional `deploy/compose.athena.yaml` uses host networking **only for this
|
||||
frontend**, binds its web server to `127.0.0.1:8118`, and connects to Deck at
|
||||
`http://127.0.0.1:8120`. This avoids changing Deck's existing network or relying on
|
||||
its current Docker IP. No Docker socket, GPU devices or inference packages are
|
||||
mounted into the GUI. CPU and RAM limits: 2 CPUs / 1 GiB.
|
||||
mounted into the GUI. CPU and RAM limits: 2 CPUs / 1 GiB. GUI identity: UID 1000 / GID 0;
|
||||
this supplies shared-file read access, not root UID or Linux capabilities.
|
||||
|
||||
Filtered Deck inventory labels:
|
||||
|
||||
@@ -17,7 +18,9 @@ Filtered Deck inventory labels:
|
||||
Media mounts:
|
||||
|
||||
- `/data/video/ltx-desktop/LTXDesktop/remote-inputs/deskweb` → writable inputs.
|
||||
A new isolated directory owned by UID/GID 1000; no recursive permission changes.
|
||||
A new isolated directory owned by UID 1000 / GID 0, mode 2750; no changes to other LTX directories.
|
||||
Files use mode 0640. The existing LTX backend runs with GID 0 and dropped
|
||||
capabilities, so group-read/traverse permission is required even for its root UID.
|
||||
- `/data/video/ltx-desktop/LTXDesktop/outputs` → read-only outputs.
|
||||
|
||||
Backend-visible input path: `/data/LTXDesktop/remote-inputs/deskweb`.
|
||||
|
||||
@@ -33,3 +33,21 @@ synthetic text upload and readback through shared input storage (test file remov
|
||||
Deck's actual Unix-socket helper inventory returns `ltx-deskweb` as `running`.
|
||||
Existing Medium, TTS, WireGuard and Deck remain running; LTX remains stopped.
|
||||
Real video generation was not requested or tested in this deployment.
|
||||
|
||||
## Shared-input permission fix — 2026-09-29
|
||||
|
||||
A real I2V request exposed a cross-container permission error: private uploads
|
||||
(0600 in a 0750 UID/GID-1000 directory) were invisible to LTX's UID/GID-0 process
|
||||
because its container drops all Linux capabilities. Same bind mount/path did not
|
||||
imply read permission. The API reported this as “Image file not found”.
|
||||
|
||||
Dedicated DeskWEB input directory now uses UID 1000 / GID 0, mode 2750; uploads,
|
||||
asset copies and thumbnails use 0640. Athena GUI runs as 1000:0 with capabilities
|
||||
still dropped. Only existing DeskWEB-owned input files had their permissions
|
||||
corrected; no other media directory, backend container or GPU service was changed.
|
||||
|
||||
Validation: build/typecheck and all 8 tests pass; integration tests now assert
|
||||
0640 on uploads, copies (including a 0600 source) and thumbnails. On Athena the
|
||||
reported image's existence/read permission was verified from inside LTX without
|
||||
opening its content. A fresh synthetic upload was also checked from LTX and then
|
||||
removed. Only the GUI was recreated; real image generation remains a user retry.
|
||||
|
||||
Reference in New Issue
Block a user