From 6422d9fa0ce75b7122adfa6f87ac7d76193e1505 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Tue, 29 Sep 2026 12:23:42 +0200 Subject: [PATCH] Container makes its data directory usable itself (closes #42) sneak's standing rule: the container makes its data directory usable itself, with no step on the host. entrypoint.sh now creates /var/lib/berlin.sneak.app.routewatch if it is missing and stops the start when any step fails (set -euo pipefail); before, a failed cd went on to change the ownership of whatever directory the script was in, and a failed chown still started the daemon. Taking ownership of the directory and switching to the routewatch user through setpriv are unchanged. The README's upaas volume line now says only which path to mount. The empty-directory and other-uid cases were run by hand on the built image with upaas-style bind mounts, not added as an automated test. Model: opus-5-5 --- README.md | 4 +--- TODO.md | 3 +++ entrypoint.sh | 4 ++++ 3 files changed, 8 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 6204266..cf77465 100644 --- a/README.md +++ b/README.md @@ -235,9 +235,7 @@ with the goroutine count and Go memory figures. What the [upaas](https://git.eeqj.de/sneak/upaas) app needs: - Container port: `8080`. -- Volume: one, at container path `/var/lib/berlin.sneak.app.routewatch`. upaas - does not create the host directory, so create it before the first deploy. The - entrypoint takes ownership of it, so a root-owned directory works. +- Volume: one, at container path `/var/lib/berlin.sneak.app.routewatch`. - Environment: nothing is required. Leave `XDG_DATA_HOME`, `GOMEMLIMIT` and `MALLOC_ARENA_MAX` at the image's values. `DEBUG=routewatch` is optional and adds the `System stats` memory line to the log. diff --git a/TODO.md b/TODO.md index 03fd25f..b967d9a 100644 --- a/TODO.md +++ b/TODO.md @@ -28,6 +28,9 @@ The other open issue is https://git.eeqj.de/sneak/routewatch/issues/30. # Completed Steps +- 2026-09-29: the entrypoint creates the data directory if it is missing and + stops the start if a step fails; README "Running under upaas" no longer + asks for the host directory to be created first (closes #42) - 2026-09-29: `.dockerignore` keeps `.git`, local build output, local databases and `.env` out of the Docker build context, and so out of the source archive in the image (closes #39) diff --git a/entrypoint.sh b/entrypoint.sh index 7679fad..50d1aed 100644 --- a/entrypoint.sh +++ b/entrypoint.sh @@ -1,4 +1,5 @@ #!/bin/bash +set -euo pipefail # glibc silently ignores a malformed MALLOC_ARENA_MAX, so refuse it here. if [[ -n "${MALLOC_ARENA_MAX:-}" && ! "$MALLOC_ARENA_MAX" =~ ^[1-9][0-9]*$ ]]; then @@ -6,6 +7,9 @@ if [[ -n "${MALLOC_ARENA_MAX:-}" && ! "$MALLOC_ARENA_MAX" =~ ^[1-9][0-9]*$ ]]; t exit 1 fi +# Give the data directory to the routewatch user before the daemon starts, +# whether it is missing, an empty root-owned mount, or holds another uid's files. +mkdir -p /var/lib/berlin.sneak.app.routewatch cd /var/lib/berlin.sneak.app.routewatch chown -R routewatch:routewatch . chmod 700 .