Repository navigation
fix: extract tool archives as root-owned (TAR_OPTIONS=--no-same-owner) - #20
Merged
Merged
Conversation
Jobs run as root, and GNU tar as root keeps the archive's owner ids, so toolchains unpacked into the tool cache (the Flutter SDK via flutter-action) belong to an unknown uid and git refuses them with 'detected dubious ownership': every flutter command exits 128. Reproduced on ubuntu 24.04 / git 2.43; with --no-same-owner the files are root-owned and git works. Rejected: safe.directory=* in the image's system gitconfig (git 2.43 has no prefix match, so it would disable the ownership check for every repository). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Jobs in this image run as root. GNU tar run as root keeps the owner ids stored in an archive by default.
subosito/flutter-actionunpacks the Flutter SDK withtar xfinto/opt/hostedtoolcache, so the SDK ends up owned by an unknown uid. The Flutter SDK is a git checkout and the flutter tool runs git on every invocation, so git refuses it and everyfluttercommand fails:GitHub-hosted runners don't hit this because they run as a non-root user, and tar never preserves ownership for non-root.
Fix
ENV TAR_OPTIONS=--no-same-owner, so root extracts files as root. This matches what a non-root runner gets, and it covers every tarball-installed toolchain, not only Flutter.Reproduced in
ubuntu:24.04(git 2.43.0): extracting an archive owned by uid 1234 as root givesowner=1234and git fails with dubious ownership. WithTAR_OPTIONS=--no-same-ownerit givesowner=0and git works.Rejected
git config --system safe.directory '*'. git 2.43 has no prefix matching forsafe.directory, so the only working value is the wildcard, which turns the ownership check off for every repository.Rollout
The tool cache is not a volume, so after the new image is deployed the recreated containers start with a clean cache, and the next Flutter job extracts it with the right owner.
🤖 Generated with Claude Code