From af4983d7478b4a8014d378558f5bd67ba90204bc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?R=C3=A2u=20Cao?= Date: Thu, 8 Oct 2026 11:51:23 +0200 Subject: [PATCH] Record revision stamps as the mastodon user The stamp files' lazy git call ran as root, which git rejects on the mastodon-owned repository (dubious ownership), silently writing an empty stamp. Use execute resources with the mastodon user instead so git works and the revision is recorded. --- site-cookbooks/kosmos-mastodon/recipes/build.rb | 16 +++++++++------- site-cookbooks/kosmos-mastodon/recipes/deploy.rb | 16 +++++++++------- 2 files changed, 18 insertions(+), 14 deletions(-) diff --git a/site-cookbooks/kosmos-mastodon/recipes/build.rb b/site-cookbooks/kosmos-mastodon/recipes/build.rb index ea369e0..839802f 100644 --- a/site-cookbooks/kosmos-mastodon/recipes/build.rb +++ b/site-cookbooks/kosmos-mastodon/recipes/build.rb @@ -179,13 +179,15 @@ execute "rake assets:precompile" do cwd mastodon_path command "bundle exec rake assets:precompile" not_if build_uptodate - notifies :create, "file[#{mastodon_path}/tmp/built-revision]", :immediately + notifies :run, "execute[record built revision]", :immediately end -file "#{mastodon_path}/tmp/built-revision" do - content lazy { `git -C #{mastodon_path} rev-parse HEAD`.strip } - owner mastodon_user - group mastodon_user - mode "0644" - action :nothing +# Record the built revision. Runs as the mastodon user so git accepts the repo +# (a root-run `git` would refuse due to dubious ownership). +execute "record built revision" do + user mastodon_user + group mastodon_user + cwd mastodon_path + command "git rev-parse HEAD > tmp/built-revision" + action :nothing end diff --git a/site-cookbooks/kosmos-mastodon/recipes/deploy.rb b/site-cookbooks/kosmos-mastodon/recipes/deploy.rb index 8346257..aebac8f 100644 --- a/site-cookbooks/kosmos-mastodon/recipes/deploy.rb +++ b/site-cookbooks/kosmos-mastodon/recipes/deploy.rb @@ -131,7 +131,7 @@ execute "tootctl search deploy (create indices)" do timeout 3_600 action :nothing notifies :run, "execute[start mastodon search deploy]", :immediately - notifies :create, "file[#{mastodon_path}/tmp/deployed-revision]", :immediately + notifies :run, "execute[record deployed revision]", :immediately end execute "start mastodon search deploy" do @@ -139,12 +139,14 @@ execute "start mastodon search deploy" do action :nothing end -file "#{mastodon_path}/tmp/deployed-revision" do - content lazy { `git -C #{mastodon_path} rev-parse HEAD`.strip } - owner mastodon_user - group mastodon_user - mode "0644" - action :nothing +# Record the deployed revision. Runs as the mastodon user so git accepts the +# repo (a root-run `git` would refuse due to dubious ownership). +execute "record deployed revision" do + user mastodon_user + group mastodon_user + cwd mastodon_path + command "git rev-parse HEAD > tmp/deployed-revision" + action :nothing end service "mastodon-web" do