Fix shared upload permissions for capability-restricted LTX backend
This commit is contained in:
@@ -33,3 +33,21 @@ synthetic text upload and readback through shared input storage (test file remov
|
||||
Deck's actual Unix-socket helper inventory returns `ltx-deskweb` as `running`.
|
||||
Existing Medium, TTS, WireGuard and Deck remain running; LTX remains stopped.
|
||||
Real video generation was not requested or tested in this deployment.
|
||||
|
||||
## Shared-input permission fix — 2026-09-29
|
||||
|
||||
A real I2V request exposed a cross-container permission error: private uploads
|
||||
(0600 in a 0750 UID/GID-1000 directory) were invisible to LTX's UID/GID-0 process
|
||||
because its container drops all Linux capabilities. Same bind mount/path did not
|
||||
imply read permission. The API reported this as “Image file not found”.
|
||||
|
||||
Dedicated DeskWEB input directory now uses UID 1000 / GID 0, mode 2750; uploads,
|
||||
asset copies and thumbnails use 0640. Athena GUI runs as 1000:0 with capabilities
|
||||
still dropped. Only existing DeskWEB-owned input files had their permissions
|
||||
corrected; no other media directory, backend container or GPU service was changed.
|
||||
|
||||
Validation: build/typecheck and all 8 tests pass; integration tests now assert
|
||||
0640 on uploads, copies (including a 0600 source) and thumbnails. On Athena the
|
||||
reported image's existence/read permission was verified from inside LTX without
|
||||
opening its content. A fresh synthetic upload was also checked from LTX and then
|
||||
removed. Only the GUI was recreated; real image generation remains a user retry.
|
||||
|
||||
Reference in New Issue
Block a user