Files
routewatch/entrypoint.sh
T
sneak 957ba4b55b
check / check (push) Successful in 3m18s
Container makes its data directory usable itself (closes #42)
The entrypoint now creates the data directory if it is missing and stops
the start when any step fails, so a failed cd can no longer change the
ownership of some other directory. It already took ownership of the
directory and dropped to the routewatch user; that is unchanged. The
README's upaas section now says only which path to mount.

Model: opus-5-5
2026-09-29 09:23:54 +00:00

21 lines
851 B
Bash

#!/bin/bash
set -euo pipefail
# glibc silently ignores a malformed MALLOC_ARENA_MAX, so refuse it here.
if [[ -n "${MALLOC_ARENA_MAX:-}" && ! "$MALLOC_ARENA_MAX" =~ ^[1-9][0-9]*$ ]]; then
echo "MALLOC_ARENA_MAX must be a positive whole number, got '$MALLOC_ARENA_MAX'" >&2
exit 1
fi
# Give the data directory to the routewatch user before the daemon starts,
# whether it is missing, an empty root-owned mount, or holds another uid's files.
mkdir -p /var/lib/berlin.sneak.app.routewatch
cd /var/lib/berlin.sneak.app.routewatch
chown -R routewatch:routewatch .
chmod 700 .
# setpriv replaces itself with the daemon, so the daemon receives the stop
# signal directly. runuser would stay in between and kill the daemon 2 seconds
# after passing the signal on.
exec setpriv --reuid=routewatch --regid=routewatch --init-groups -- /app/routewatch