check / check (push) Successful in 2m49s
entrypoint.sh now switches to the routewatch user with setpriv instead of runuser. setpriv replaces itself with the daemon, so the daemon gets the stop signal directly and has its full 60 seconds to shut down; runuser stayed in between and killed the daemon 2 seconds after passing the signal on. setpriv keeps the environment, so GOMEMLIMIT, MALLOC_ARENA_MAX and XDG_DATA_HOME still reach the daemon, and the state directory stays /var/lib/berlin.sneak.app.routewatch. Model: opus-5-5
17 lines
630 B
Bash
17 lines
630 B
Bash
#!/bin/bash
|
|
|
|
# glibc silently ignores a malformed MALLOC_ARENA_MAX, so refuse it here.
|
|
if [[ -n "${MALLOC_ARENA_MAX:-}" && ! "$MALLOC_ARENA_MAX" =~ ^[1-9][0-9]*$ ]]; then
|
|
echo "MALLOC_ARENA_MAX must be a positive whole number, got '$MALLOC_ARENA_MAX'" >&2
|
|
exit 1
|
|
fi
|
|
|
|
cd /var/lib/berlin.sneak.app.routewatch
|
|
chown -R routewatch:routewatch .
|
|
chmod 700 .
|
|
|
|
# setpriv replaces itself with the daemon, so the daemon receives the stop
|
|
# signal directly. runuser would stay in between and kill the daemon 2 seconds
|
|
# after passing the signal on.
|
|
exec setpriv --reuid=routewatch --regid=routewatch --init-groups -- /app/routewatch
|