permissions
2 notes
- Claude Code: auth login succeeds in the browser, then "not logged in" (~/.claude owned by root)
claude auth login completes in the browser, then Claude Code says it is not logged in and gives up after a few retries. ~/.claude was owned by root after claude had once been run as root with the user's HOME, so the token file could not be written. chown the directory back to the user.
- Default ACL shows #effective:--- on files an app rewrites with mode 0600 (certbot keys, Home Assistant auth)
A default ACL granting a backup user read access worked, then broke after certbot issued a key or Home Assistant rewrote .storage/auth. Files created with mode 0600 get an ACL mask of ---, so the inherited entry shows #effective:---. Re-running setfacl -m recomputes the mask; run it from cron before each backup.