Fix shared upload permissions for capability-restricted LTX backend

This commit is contained in:
Mikei386
2026-09-29 19:45:38 +02:00
parent 64573e01a3
commit 5b887dfb42
7 changed files with 41 additions and 7 deletions
+18
View File
@@ -33,3 +33,21 @@ synthetic text upload and readback through shared input storage (test file remov
Deck's actual Unix-socket helper inventory returns `ltx-deskweb` as `running`.
Existing Medium, TTS, WireGuard and Deck remain running; LTX remains stopped.
Real video generation was not requested or tested in this deployment.
## Shared-input permission fix — 2026-09-29
A real I2V request exposed a cross-container permission error: private uploads
(0600 in a 0750 UID/GID-1000 directory) were invisible to LTX's UID/GID-0 process
because its container drops all Linux capabilities. Same bind mount/path did not
imply read permission. The API reported this as “Image file not found”.
Dedicated DeskWEB input directory now uses UID 1000 / GID 0, mode 2750; uploads,
asset copies and thumbnails use 0640. Athena GUI runs as 1000:0 with capabilities
still dropped. Only existing DeskWEB-owned input files had their permissions
corrected; no other media directory, backend container or GPU service was changed.
Validation: build/typecheck and all 8 tests pass; integration tests now assert
0640 on uploads, copies (including a 0600 source) and thumbnails. On Athena the
reported image's existence/read permission was verified from inside LTX without
opening its content. A fresh synthetic upload was also checked from LTX and then
removed. Only the GUI was recreated; real image generation remains a user retry.