From e26e25d61889f3482fea3467ec812ef514d10fe5 Mon Sep 17 00:00:00 2001 From: Ben Barclay Date: Tue, 25 Aug 2026 10:56:24 +1000 Subject: [PATCH] docs: add operator remediation for install dirs locked to 0700 by older images The Dockerfile fix in #93757 only helps newly built images, and an image upgrade (container recreate) resets the permission because /opt/hermes lives in the image layer. The one stranded case is an old image whose container was stopped and restarted after the lockout: it keeps the 0700 install dir and runs code without the guard. Document the one-line in-place recovery (chmod 0755 /opt/hermes as root) in the Docker troubleshooting section. Follow-up to #93757. --- website/docs/user-guide/docker.md | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/website/docs/user-guide/docker.md b/website/docs/user-guide/docker.md index cf63f4f6eb..747e6b40ed 100644 --- a/website/docs/user-guide/docker.md +++ b/website/docs/user-guide/docker.md @@ -802,6 +802,16 @@ docker run -d \ `docker exec hermes ` automatically drops to UID 10000 too — see [`docker exec` automatically drops to the `hermes` user](#docker-exec-automatically-drops-to-the-hermes-user) for details and the per-invocation opt-out. +### "Permission denied" on every `docker exec` (install dir locked to 0700) + +Images built before late August 2026 had a bug where writing a credential file directly under `/opt/hermes` restricted that directory to `0700`, locking the `hermes` user (UID 10000) out of the install tree. Every new `docker exec` then fails with `Permission denied`. + +Pulling a newer image and recreating the container fixes it permanently (the install dir ships as `0755` and current releases no longer restrict it). If you need to recover a running container in place without recreating it: + +```sh +docker exec -u root hermes chmod 0755 /opt/hermes +``` + ### Browser tools not working Playwright needs shared memory. Add `--shm-size=1g` to your Docker run command: