{"record":{"id":"a88c5aad89849ab5","repo":"jdx/mise","slug":"cannot-determine-the-current-user-to-own-prefix","errorCode":null,"errorMessage":"cannot determine the current user to own {prefix}","messagePattern":"cannot determine the current user to own (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/system/packages/brew/prefix.rs","lineNumber":204,"sourceCode":"    let missing_subdirs: Vec<PathBuf> = dirs.iter().filter(|p| !p.exists()).cloned().collect();\n    if !needs_create && !needs_chown && missing_subdirs.is_empty() {\n        return Ok(());\n    }\n    // try without elevation first — covers prefixes under user-writable\n    // parents; the real prefixes need sudo to create. Skipped under `sudo\n    // mise`: root could create the dirs, but they must be chowned to the\n    // invoking user afterwards\n    if needs_create\n        && !dry_run\n        && sudo_invoking_user().is_none()\n        && dirs.iter().try_for_each(std::fs::create_dir_all).is_ok()\n    {\n        return Ok(());\n    }\n    if needs_create || needs_chown {\n        let Some(user) = prefix_owner() else {\n            // never chown to a guessed owner — that can lock the user out\n            bail!(\n                \"cannot determine the current user to own {}\",\n                prefix.display()\n            );\n        };\n        // brew's install.sh chowns to user:admin on macOS, just the user on\n        // Linux (the admin group doesn't exist there)\n        let owner = if cfg!(target_os = \"macos\") {\n            format!(\"{user}:admin\")\n        } else {\n            user\n        };\n        let mut mkdir_dirs: Vec<String> = vec![prefix.to_string_lossy().to_string()];\n        mkdir_dirs.extend(dirs.iter().map(|d| d.display().to_string()));\n        let mkdir_args: Vec<String> = [\"-p\".to_string()].into_iter().chain(mkdir_dirs).collect();\n        let chown_args: Vec<String> = vec![\"-R\".to_string(), owner, prefix.display().to_string()];\n        if dry_run {\n            miseprintln!(\"{}\", sudo::argv(\"mkdir\", &mkdir_args).join(\" \"));\n            miseprintln!(\"{}\", sudo::argv(\"chown\", &chown_args).join(\" \"));","sourceCodeStart":186,"sourceCodeEnd":222,"githubUrl":"https://github.com/jdx/mise/blob/533346cc374382b41ec5ff70536252b2e96e725c/src/system/packages/brew/prefix.rs#L186-L222","documentation":"bootstrap creates and chowns the brew prefix to the current user (or SUDO_USER under sudo mise). It deliberately refuses to guess an owner: prefix_owner() returns None when there is no invoking sudo user and the effective uid cannot be resolved to a username (e.g. plain root in a container without a passwd entry, or a deleted user). Chowning to a guessed owner could lock the real user out, so mise errors instead.","triggerScenarios":"bootstrap needs to create the prefix or chown it (needs_create || needs_chown) but prefix_owner() returns None — running as plain root with no SUDO_USER and no passwd entry for uid 0's name lookup, or SUDO_USER names a nonexistent user.","commonSituations":"`sudo mise ...` where SUDO_USER is set to a user deleted from /etc/passwd; docker run as root in minimal images with an empty/broken /etc/passwd; nixpkgs/static-linking edge cases where nix::unistd::User::from_uid fails.","solutions":["Run mise as a normal user instead of root, or ensure SUDO_USER is correct when using sudo","Fix the container's /etc/passwd so the current uid maps to a username (e.g. ensure root:x:0:0:root:/root:/bin/sh exists)","Pre-create the prefix yourself with correct ownership (mkdir + chown to your user) so bootstrap finds it writable and skips the chown path"],"exampleFix":"# before (docker)\nUSER root\nRUN mise bootstrap packages apply\n# after\nRUN mkdir -p /home/linuxbrew/.linuxbrew && chown -R developer /home/linuxbrew\nUSER developer","handlingStrategy":"validation","validationCode":"u=\"${SUDO_USER:-$(id -un)}\"\nid \"$u\" >/dev/null 2>&1 || echo \"owner user '$u' does not resolve — fix /etc/passwd or SUDO_USER\"","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Run mise as a real named user, not bare root in passwd-less containers","Ensure SUDO_USER points to an existing account when using sudo mise","Pre-create and chown the brew prefix in image builds so bootstrap never needs to determine an owner"],"tags":["brew","permissions","ownership"],"backgroundTag":"missing-credentials","analyzedSha":"533346cc374382b41ec5ff70536252b2e96e725c","analyzedAt":"2026-09-17T13:35:38.149Z","contentChangedAt":"2026-09-17T13:35:38.149Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}