diff --git a/Dockerfile b/Dockerfile index 83d9ed0..cedd1c9 100644 --- a/Dockerfile +++ b/Dockerfile @@ -79,8 +79,8 @@ RUN chown -R routewatch:routewatch /app ENV XDG_DATA_HOME=/var/lib # Cap the Go heap at 1.5 GiB so the runtime collects harder before the -# container's memory limit is reached. runuser preserves this the way it does -# XDG_DATA_HOME above. +# container's memory limit is reached. setpriv in the entrypoint preserves this +# the way it does XDG_DATA_HOME above. ENV GOMEMLIMIT=1536MiB # Cap glibc's malloc arenas. The SQLite C library allocates and frees millions diff --git a/TODO.md b/TODO.md index fea8ac6..fc94648 100644 --- a/TODO.md +++ b/TODO.md @@ -23,6 +23,10 @@ runs make check on main. # Completed Steps +- 2026-09-28: `docker stop` no longer kills the daemon 2 seconds after the + stop signal: the entrypoint switches to the `routewatch` user with + `setpriv` instead of `runuser`, so the daemon receives the signal itself + and gets its full 60 seconds to shut down (closes #33) - 2026-09-28: ready to run under upaas: a set but invalid `PORT`, `XDG_DATA_HOME` or `MALLOC_ARENA_MAX` stops the start, the health check follows `PORT`, README "Running under upaas" section (closes diff --git a/entrypoint.sh b/entrypoint.sh index 3f0d092..7679fad 100644 --- a/entrypoint.sh +++ b/entrypoint.sh @@ -10,4 +10,7 @@ cd /var/lib/berlin.sneak.app.routewatch chown -R routewatch:routewatch . chmod 700 . -exec runuser -u routewatch -- /app/routewatch +# setpriv replaces itself with the daemon, so the daemon receives the stop +# signal directly. runuser would stay in between and kill the daemon 2 seconds +# after passing the signal on. +exec setpriv --reuid=routewatch --regid=routewatch --init-groups -- /app/routewatch