Skip to content

tmp-sticky

Version 2026.267.1305
Repo box/cachyos

Restores /tmp to the distro-standard world-writable sticky mode (1777) at image-build time, and asserts it. Some build steps leave a consumer image’s /tmp at root:root 0755, after which every uid-1000 writer of /tmp fails — supervisord’s logfile=/tmp/supervisord.log and pod-dbus’s unix:path=/tmp/dbus-session both EACCES at startup.

Root cause (RCA 2026-09-24): a BuildKit cache mount rooted UNDER /tmp (--mount=type=cache,...,dst=/tmp/...) combined with a nested container runtime that writes under /tmp in the same RUN makes BuildKit materialise /tmp at the process umask (0755) instead of preserving the lower layer’s 1777. charly’s build vocabulary emitted exactly that for command: steps (non-root cache dst=/tmp/npm-cache) and for download: steps (cache dst=/tmp/downloads); a box composing layer-container-nesting (whose pre-pull step is a command: with that cache) therefore shipped a broken /tmp. The chary SDK’s cache destinations moving OFF /tmp is the root fix; this candy is the box-level guarantee that /tmp is correct in the built image regardless of which candy in the chain was responsible, and is the single home for the normalization (R3) — it composes LAST so its step runs after every other candy’s steps.

This candy’s plan: — the runnable spec charly check executes against a live deployment. check: steps are idempotent probes; run: steps change state.

Intent Step
run restore /tmp to world-writable sticky (1777) after any build step that left it 0755 (see description; RCA 2026-09-24)
check /tmp in the built image carries the distro-standard world-writable sticky mode (1777)