diff --git a/Dockerfile b/Dockerfile index 30aace9..5c52dfb 100644 --- a/Dockerfile +++ b/Dockerfile @@ -79,6 +79,15 @@ RUN git checkout --quiet --detach b4b2c785308b1ce785b6155c7fe5f16879080193 \ # ubuntu 26.04, 2026-09-27 FROM ubuntu@sha256:f144425ff09be612d6d9ad965196e9cdc23dae1f42110a8a11a3e9a8198759f7 +# runit's install creates its _runit-log user with minsysusers, which +# reads this file in place of runit's /usr/lib/sysusers.d/runit.conf. +# runit's line leaves out the shell, and minsysusers prints a Perl +# warning for that; this copy of it names /sbin/nologin, the shell +# minsysusers gives when none is named. +RUN mkdir /etc/sysusers.d \ + && echo 'u _runit-log - "runit svlogd user" /nonexistent /sbin/nologin' \ + > /etc/sysusers.d/runit.conf + # ca-certificates, nix-bin and runit, from Ubuntu's archive as it was at # the snapshot moment, which is never earlier than the Ubuntu image above. # apt checks every package against the snapshot's InRelease files, and @@ -130,9 +139,12 @@ ENV PATH=${PATH}:/nix/var/nix/profiles/default/bin COPY --from=runsvinit /usr/local/bin/runsvinit /usr/local/bin/runsvinit COPY --from=builder /usr/local/bin/smallwebwaf /usr/local/bin/smallwebwaf +# 65532 is above the uids Ubuntu keeps for system users, which end at +# 999; useradd warns about it unless --key raises that end for this call. RUN groupadd --system --gid 65532 smallwebwaf \ - && useradd --system --uid 65532 --gid smallwebwaf --no-create-home \ - --shell /usr/sbin/nologin smallwebwaf + && useradd --system --key SYS_UID_MAX=65532 --uid 65532 \ + --gid smallwebwaf --no-create-home --shell /usr/sbin/nologin \ + smallwebwaf # runsvinit starts runit's runsvdir on /etc/service, where Ubuntu's sv # looks too.