Container makes /var/lib/pixa usable before starting pixad (closes #159)
check / check (push) Successful in 3m44s

The entrypoint now creates /var/lib/pixa if it is missing. When the
directory or one of its top-level entries belongs to another user or
group, it gives the whole tree to pixad (uid and gid 65532); it then
sets the directory's mode to 750 and runs the server as pixad as
before. Data left by a run under another uid is taken over this way.
Only the top level is checked, so a normal start does not walk the
cache; the tree is changed deepest first, so an interrupted start is
finished by the next one.

"Running under upaas" in README.md no longer tells the operator to
create or chown the host directory.

Model: opus-5-5
This commit is contained in:
2026-09-29 10:28:08 +00:00
parent bce8860c2e
commit 08f8c25349
3 changed files with 22 additions and 12 deletions
+13 -5
View File
@@ -1,14 +1,22 @@
#!/bin/sh
# deploy/docker-entrypoint.sh: the Docker image's ENTRYPOINT. It runs as
# root only to give /var/lib/pixa to pixad: a host directory
# bind-mounted there keeps its host owner, often root, and pixad could
# not write to it. The server itself always runs as pixad.
# root only to make /var/lib/pixa usable by pixad: a host directory
# bind-mounted there keeps its host owner, often root, and data from an
# earlier run may belong to another uid. The server itself always runs
# as pixad.
set -eu
main() {
if [ "$(stat -c %U /var/lib/pixa)" != pixad ]; then
chown pixad:pixad /var/lib/pixa
mkdir -p /var/lib/pixa
# Only the directory and its top-level entries are checked, so a
# normal start does not walk the cache. -depth gives each directory
# to pixad after its contents, so a start stopped part way leaves
# something at the top for the next start to find; -h changes a
# symlink itself, never the file it points to.
if [ -n "$(find /var/lib/pixa -maxdepth 1 \( ! -user pixad -o ! -group pixad \))" ]; then
find /var/lib/pixa -depth -exec chown -h pixad:pixad {} +
fi
chmod 750 /var/lib/pixa
exec su-exec pixad /usr/local/bin/pixad "$@"
}