check / check (push) Successful in 8s
sneak's standing rule: the container makes its data directory usable itself, with no step on the host. entrypoint.sh now creates /var/lib/berlin.sneak.app.routewatch if it is missing and stops the start when any step fails (set -euo pipefail); before, a failed cd went on to change the ownership of whatever directory the script was in, and a failed chown still started the daemon. Taking ownership of the directory and switching to the routewatch user through setpriv are unchanged. The README's upaas volume line now says only which path to mount. The empty-directory and other-uid cases were run by hand on the built image with upaas-style bind mounts, not added as an automated test. Model: opus-5-5
21 lines
851 B
Bash
21 lines
851 B
Bash
#!/bin/bash
|
|
set -euo pipefail
|
|
|
|
# glibc silently ignores a malformed MALLOC_ARENA_MAX, so refuse it here.
|
|
if [[ -n "${MALLOC_ARENA_MAX:-}" && ! "$MALLOC_ARENA_MAX" =~ ^[1-9][0-9]*$ ]]; then
|
|
echo "MALLOC_ARENA_MAX must be a positive whole number, got '$MALLOC_ARENA_MAX'" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Give the data directory to the routewatch user before the daemon starts,
|
|
# whether it is missing, an empty root-owned mount, or holds another uid's files.
|
|
mkdir -p /var/lib/berlin.sneak.app.routewatch
|
|
cd /var/lib/berlin.sneak.app.routewatch
|
|
chown -R routewatch:routewatch .
|
|
chmod 700 .
|
|
|
|
# setpriv replaces itself with the daemon, so the daemon receives the stop
|
|
# signal directly. runuser would stay in between and kill the daemon 2 seconds
|
|
# after passing the signal on.
|
|
exec setpriv --reuid=routewatch --regid=routewatch --init-groups -- /app/routewatch
|