diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 7977ac09c3..b9de0c5d1e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -139,6 +139,14 @@ jobs: # root-owned, and the ZMQ IPC sockets live in it docker exec frigate /command/s6-setuidgid frigate touch /tmp/cache/.write-probe docker exec frigate rm /tmp/cache/.write-probe + # bundled models must be readable by the runtime user: they are baked + # in as root, and archive members can carry root-only modes + docker exec frigate /command/s6-setuidgid frigate sh -c ' + for f in /cpu_model.tflite /edgetpu_model.tflite /cpu_audio_model.tflite \ + /labelmap.txt /audio-labelmap.txt /openvino-model/*; do + [ -e "$f" ] || continue + test -r "$f" || { echo "$f is not readable by the runtime user"; exit 1; } + done' - name: Assert escape hatch restores root run: | mkdir -p /tmp/frigate-config-root diff --git a/docker/main/Dockerfile b/docker/main/Dockerfile index c714fda963..cc551429c0 100644 --- a/docker/main/Dockerfile +++ b/docker/main/Dockerfile @@ -146,6 +146,10 @@ RUN wget -q https://github.com/openvinotoolkit/open_model_zoo/raw/master/data/da RUN wget -qO - https://www.kaggle.com/api/v1/models/google/yamnet/tfLite/classification-tflite/1/download | tar xvz && mv 1.tflite cpu_audio_model.tflite COPY audio-labelmap.txt . +# tar restores the archive's modes and the yamnet member ships 0700, so without +# this the unprivileged runtime user cannot read the audio model +RUN chmod -R a+rX /rootfs + FROM wget AS s6-overlay ARG TARGETARCH