Skip to content

ci: run Cacti poller as www-data instead of root - #34

Merged
TheWitness merged 2 commits into
mainfrom
ci/poller-as-www-data
Sep 15, 2026
Merged

TheWitness merged 2 commits into
mainfrom
ci/poller-as-www-data

Conversation

@TheWitness

Copy link
Copy Markdown
Member

The integration test workflow ran \poller.php\ via \sudo\ (root). This re-chowns the Cacti tree to \www-data:runner\ right before polling and runs the poller as \www-data\ instead, matching how Cacti expects the poller to run in production. This also sidesteps Cacti core's root-only RRD ownership-assignment code path in
rdtool_function_create().

Re-chown the Cacti tree to www-data:runner right before polling (the
CLI install steps run as root and create some files as root), then
invoke poller.php via 'sudo -u www-data' so it runs as the actual
web/poller user instead of root. This also avoids Cacti core's
root-only RRD chown/chgrp path in rrdtool_function_create(), which
can log spurious 'does not exist for ownership assignment' warnings
for data sources that never produced a value.
Copilot AI lite review requested due to automatic review settings September 14, 2026 20:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved issues were identified.

Pull request overview

Updates the CI workflow to run Cacti’s poller as www-data, matching production behavior.

Changes:

  • Reapplies Cacti ownership and permissions.
  • Runs poller.php as www-data instead of root.
File summaries
File Summary
.github/workflows/plugin-ci-workflow.yml Adjusts ownership, permissions, and poller execution user.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Running the poller as www-data (instead of root) exposes that
directories above the checkout are typically 750 owned by the runner
user, so a non-root www-data process has no 'x' permission to even
traverse into them. Root's DAC-bypass previously masked this. Walk up
from github.workspace and add o+x to each ancestor directory before
polling.
@TheWitness
TheWitness merged commit 1f45018 into main Sep 15, 2026
3 checks passed
@TheWitness
TheWitness deleted the ci/poller-as-www-data branch September 15, 2026 12:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants