diff --git a/scripts/entrypoint.sh b/scripts/entrypoint.sh index 710469df..a3691808 100755 --- a/scripts/entrypoint.sh +++ b/scripts/entrypoint.sh @@ -1,18 +1,25 @@ #!/usr/bin/env sh -# Fix ownership of data directory for users upgrading from older versions -# where files were created as root +# Fix ownership of the data directory (e.g. for users upgrading from older +# versions where files were created as root) and drop to a non-root user. MEMOS_UID=${MEMOS_UID:-10001} MEMOS_GID=${MEMOS_GID:-10001} DATA_DIR="/var/opt/memos" -if [ "$(id -u)" = "0" ]; then - # Running as root, fix permissions and drop to nonroot +# MEMOS_ENTRYPOINT_SWITCHED marks that the privilege drop below has already run. +# su-exec preserves the environment, so the marker survives the re-exec. Without +# it, a target of UID 0 (e.g. MEMOS_UID=0, common under rootless Docker) would +# stay root after su-exec, re-enter this block, and loop forever. +if [ "$(id -u)" = "0" ] && [ -z "${MEMOS_ENTRYPOINT_SWITCHED:-}" ]; then + # Started as root: fix permissions, then re-exec as the target user. if [ -d "$DATA_DIR" ]; then chown -R "$MEMOS_UID:$MEMOS_GID" "$DATA_DIR" 2>/dev/null || true fi + echo "memos: starting as UID:GID ${MEMOS_UID}:${MEMOS_GID}" + export MEMOS_ENTRYPOINT_SWITCHED=1 exec su-exec "$MEMOS_UID:$MEMOS_GID" "$0" "$@" fi +unset MEMOS_ENTRYPOINT_SWITCHED file_env() { var="$1"