check / check (push) Successful in 3m18s
The entrypoint now creates the data directory if it is missing and stops the start when any step fails, so a failed cd can no longer change the ownership of some other directory. It already took ownership of the directory and dropped to the routewatch user; that is unchanged. The README's upaas section now says only which path to mount. Model: opus-5-5
21 lines
851 B
Bash
21 lines
851 B
Bash
#!/bin/bash
|
|
set -euo pipefail
|
|
|
|
# glibc silently ignores a malformed MALLOC_ARENA_MAX, so refuse it here.
|
|
if [[ -n "${MALLOC_ARENA_MAX:-}" && ! "$MALLOC_ARENA_MAX" =~ ^[1-9][0-9]*$ ]]; then
|
|
echo "MALLOC_ARENA_MAX must be a positive whole number, got '$MALLOC_ARENA_MAX'" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Give the data directory to the routewatch user before the daemon starts,
|
|
# whether it is missing, an empty root-owned mount, or holds another uid's files.
|
|
mkdir -p /var/lib/berlin.sneak.app.routewatch
|
|
cd /var/lib/berlin.sneak.app.routewatch
|
|
chown -R routewatch:routewatch .
|
|
chmod 700 .
|
|
|
|
# setpriv replaces itself with the daemon, so the daemon receives the stop
|
|
# signal directly. runuser would stay in between and kill the daemon 2 seconds
|
|
# after passing the signal on.
|
|
exec setpriv --reuid=routewatch --regid=routewatch --init-groups -- /app/routewatch
|