The daemon is no longer killed 2 seconds after the stop signal, so it
gets the whole wait docker stop allows, up to its own 60-second limit;
it does not always get 60 seconds.
Model: opus-5-5
entrypoint.sh now switches to the routewatch user with setpriv instead of
runuser. setpriv replaces itself with the daemon, so the daemon gets the stop
signal directly and has its full 60 seconds to shut down; runuser stayed in
between and killed the daemon 2 seconds after passing the signal on. setpriv
keeps the environment, so GOMEMLIMIT, MALLOC_ARENA_MAX and XDG_DATA_HOME still
reach the daemon, and the state directory stays
/var/lib/berlin.sneak.app.routewatch.
Model: opus-5-5