Commit 5024a43
fix: tolerate read-only filesystem when locating tool config (#1125)
`:latest` crashed at startup under hardened Docker setups (`read_only: true`,
`user: 1000:1000`) because `_get_config_path()` did an unconditional
`mkdir(parents=True, exist_ok=True)` on `Path.home() / ".ha-mcp"`. Two
contributing factors:
1. The Dockerfile didn't set `ENV HOME`, so under `USER mcpuser` Docker
left `HOME=/`. `Path.home()` resolved to `/`, ha-mcp tried to mkdir
`/.ha-mcp`, and `read_only: true` made that fatal (issue #1125).
2. Even on writable filesystems this silently polluted the container's
filesystem root with a `/.ha-mcp/` directory.
Coordinated changes:
- `settings_ui.py::_resolve_config_path`: honor a new `HA_MCP_CONFIG_DIR`
env var (explicit override for hardened Docker setups bind-mounting a
writable volume), and wrap the home-dir mkdir in `try/except OSError` so
we fall back to a tmpdir path instead of crashing. HA_MCP_CONFIG_DIR
failure also chains into the tmpdir fallback (mirrors the home-dir
branch's behavior). Result is memoized at module level via
`_CONFIG_PATH_CACHE` so the warning emits once at startup, not on every
save/load HTTP request.
- `settings_ui.py::load_tool_config`: replace the `path.exists()` /
`read_text()` two-step with a single `try: read_text() except OSError:`.
`Path.exists()` only swallows ENOENT/ENOTDIR/EBADF/ELOOP — EACCES
propagates, which would re-introduce the same class of crash if
`HA_MCP_CONFIG_DIR` pointed at a dir whose parent isn't traversable by
the runtime UID.
- `Dockerfile`: set `ENV HOME=/home/mcpuser` so `Path.home()` resolves
correctly under the default user (default-user setups now persist
settings to `~/.ha-mcp` instead of `/.ha-mcp`).
- `Dockerfile`: `chmod 0755 /home/mcpuser`. The base image's
`/etc/login.defs` sets `HOME_MODE=0700`; that's fine when the container
runs as mcpuser, but un-traversable for users that override
`--user UID:GID` (the issue reporter does so). Anything that stats a
path under HOME (set above) then raises PermissionError. Making the
dir mode 0755 keeps it traversable for any uid; write access stays
restricted to mcpuser.
Tests: 5 unit tests in `TestConfigPath`:
- HA_MCP_CONFIG_DIR overrides SUPERVISOR_TOKEN
- Falls back to tmpdir when home is unwritable (#1125 regression)
- HA_MCP_CONFIG_DIR mkdir failure chains to tmpdir fallback
- load_tool_config doesn't crash when path's parent is unreadable
- Fallback warning emits once via module cache (no log spam)
Verified locally with three Docker scenarios: bondskin's hardened compose
(`--read-only --user 1000:1000 --tmpfs /tmp`), default user, and
`HA_MCP_CONFIG_DIR=/data/ha-mcp` bind-mount. Server starts cleanly in all
three; original stack trace from #1125 no longer reproduces.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent 29397dc commit 5024a43
3 files changed
Lines changed: 287 additions & 12 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
34 | | - | |
35 | | - | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
36 | 42 | | |
37 | 43 | | |
38 | 44 | | |
| |||
43 | 49 | | |
44 | 50 | | |
45 | 51 | | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
46 | 58 | | |
47 | 59 | | |
48 | 60 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
| 15 | + | |
15 | 16 | | |
16 | 17 | | |
17 | 18 | | |
| |||
111 | 112 | | |
112 | 113 | | |
113 | 114 | | |
114 | | - | |
115 | | - | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
116 | 157 | | |
117 | 158 | | |
118 | | - | |
119 | | - | |
120 | | - | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
121 | 200 | | |
122 | 201 | | |
123 | 202 | | |
124 | 203 | | |
125 | 204 | | |
126 | | - | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
127 | 218 | | |
128 | | - | |
| 219 | + | |
129 | 220 | | |
130 | | - | |
131 | | - | |
| 221 | + | |
| 222 | + | |
132 | 223 | | |
133 | 224 | | |
134 | 225 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
137 | 137 | | |
138 | 138 | | |
139 | 139 | | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
140 | 150 | | |
141 | | - | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
142 | 155 | | |
143 | 156 | | |
144 | 157 | | |
| 158 | + | |
145 | 159 | | |
146 | 160 | | |
147 | 161 | | |
148 | 162 | | |
| 163 | + | |
149 | 164 | | |
150 | 165 | | |
151 | 166 | | |
152 | 167 | | |
153 | 168 | | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
| 317 | + | |
| 318 | + | |
| 319 | + | |
| 320 | + | |
| 321 | + | |
| 322 | + | |
| 323 | + | |
| 324 | + | |
| 325 | + | |
154 | 326 | | |
155 | 327 | | |
156 | 328 | | |
| |||
0 commit comments