Files
ProxMenux/oci/remote/unshift_oci_rootfs.py
T
MacRimiandClaude Opus 5 bcabcb618c feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.

Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.

Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
  which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
  that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
  instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources

Audit & Report:
- findings that moved in the wrong direction between runs are reported
  alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
  do next

Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
  instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes

The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 18:24:59 +02:00

67 lines
2.1 KiB
Python

#!/usr/bin/env python3
"""Convert an OCI rootfs imported with the default LXC idmap to host IDs."""
from __future__ import annotations
import os
import stat
import sys
from oci_ui import log, translate
def iter_paths(root: str):
yield root
for directory, names, files in os.walk(root, topdown=True, followlinks=False):
for name in names:
yield os.path.join(directory, name)
for name in files:
yield os.path.join(directory, name)
def note(text: str) -> None:
"""Progress goes to the run log; without one, to stderr."""
path = os.environ.get("OCI_LOG")
try:
if path:
log(path, text)
return
except OSError:
pass
print(text, file=sys.stderr, flush=True)
def main() -> int:
if len(sys.argv) != 2:
print(f"{translate('Usage:')} {sys.argv[0]} ROOTFS", file=sys.stderr)
return 2
root = os.path.realpath(sys.argv[1])
if not root.startswith("/var/lib/lxc/") or not root.endswith("/rootfs"):
print(f"{translate('Refusing an unexpected rootfs path:')} {root}", file=sys.stderr)
return 2
root_device = os.lstat(root).st_dev
shifted = 0
for path in iter_paths(root):
metadata = os.lstat(path)
if metadata.st_dev != root_device:
continue
uid = metadata.st_uid - 100000 if 100000 <= metadata.st_uid < 165536 else metadata.st_uid
gid = metadata.st_gid - 100000 if 100000 <= metadata.st_gid < 165536 else metadata.st_gid
if uid == metadata.st_uid and gid == metadata.st_gid:
continue
attributes: dict[str, bytes] = {}
for name in os.listxattr(path, follow_symlinks=False):
attributes[name] = os.getxattr(path, name, follow_symlinks=False)
os.chown(path, uid, gid, follow_symlinks=False)
for name, value in attributes.items():
os.setxattr(path, name, value, follow_symlinks=False)
shifted += 1
if shifted % 10000 == 0:
note(f" Owners converted: {shifted}")
note(f"OCI rootfs converted to privileged: {shifted} entries")
return 0
if __name__ == "__main__":
raise SystemExit(main())