Skip to content

fix(workspaces): chown ephemeral WP core so wp-admin installs pick direct FS - #9

Merged
pcfreak30 merged 1 commit into
developfrom
fix/wp-core-ownership
Sep 24, 2026
Merged

pcfreak30 merged 1 commit into
developfrom
fix/wp-core-ownership

Conversation

@pcfreak30

@pcfreak30 pcfreak30 commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Copies of WordPress core under /var/www/html were left root-owned, so get_filesystem_method() failed its owner comparison and wp-admin plugin installs fell back to FTP and failed with an unable-to-connect error. wp-init.sh now chowns the docroot, wp-admin, wp-includes and top-level core files to the runtime user on every boot, without recursing into the persistent wp-content mounts. The end-to-end verifier asserts the core owner matches the runtime uid.


Description

Fixes WordPress admin plugin/theme installs failing with unable_to_connect_to_filesystem because the WordPress core files were owned by root.

Problem

WordPress decides which filesystem method to use via get_filesystem_method(). It only selects the direct method when the runtime user owns the core files it compares against its temp-file probe. Because the WordPress core was copied as root (cp -a from /usr/src) and left root-owned, the filesystem check failed and WP fell back to FTP/credentials mode, which cannot work in this containerized environment.

Changes

  • images/wordpress/wp-init.sh
    • Added fix_core_ownership() which changes ownership of the WordPress core files (docroot, wp-admin/, wp-includes/, and top-level files) to the runtime application user.
    • The function is called on every boot so newly recreated docroots are also fixed.
    • It deliberately does not recurse into wp-content/ because persistent mounts there can be arbitrarily large (especially uploads/).
    • Updated related comments to reflect the new ownership strategy.
  • scripts/verify-wordpress.sh
    • Added a verification check that the runtime user owns /var/www/html/wp-admin/includes/file.php, ensuring the direct filesystem method will be used going forward.

Impact

WordPress admin can now install, update, and delete plugins/themes through the UI without filesystem credential errors.

@kody-ai

kody-ai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Kody Review Complete

Great news! 🎉
No issues were found that match your current review configurations.

Keep up the excellent work! 🚀

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the @kody start-review command at the root of your PR.

  • Validate Business Logic: Ask Kody to validate your code against business rules by adding a comment with the @kody -v business-logic command.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

​

@pcfreak30
pcfreak30 marked this pull request as ready for review September 24, 2026 23:02
@pcfreak30
pcfreak30 merged commit 9478c92 into develop Sep 24, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant