Docker on the dev boxes is rootful, so without `--user` every byte the build
writes into the bind-mounted repo is owned by root and the user needs `sudo` to
delete their own artifacts. This is not hypothetical: `export/` in a working
tree held 227 root-owned paths (149 MB) from earlier runs, and the `sylpheed.db`
regen in the workspace CLAUDE.md writes straight into /work, so it lands
root-owned every time.
The catch is that the daemon creates a named volume root-owned, so a `--user`
container cannot write /cargo or /target at all. So take ownership of both
volumes first -- once, and only when it is actually wrong, since a recursive
chown across a ~36 GB target volume is not something to repeat per invocation.
Both are sampled, not just one, because an older run can leave them drifted.
Volume names become overridable (SYLPH_CI_CARGO_VOL / SYLPH_CI_TARGET_VOL),
which is what let the chown path be tested without touching the real caches.
Placed above the corpus-mount block so it does not collide with #53.
Measured, not assumed:
* fresh root-owned volumes -> chowns once, then writes as uid 1000
* second run -> no chown, correctly cached
* `cargo check -p sylpheed-ppc` through the runner -> passes, exit 0
* a file touched in /work -> owned fabi:fabi, removable without sudo
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>