From 7530590066cb750ccb04c5453cae1ef1575177b5 Mon Sep 17 00:00:00 2001 From: Josh Hawkins <32435876+hawkeye217@users.noreply.github.com> Date: Sun, 23 Aug 2026 17:59:19 -0500 Subject: [PATCH] Run go2rtc as its own restricted user --- .../main/rootfs/etc/s6-overlay/s6-rc.d/go2rtc/run | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/docker/main/rootfs/etc/s6-overlay/s6-rc.d/go2rtc/run b/docker/main/rootfs/etc/s6-overlay/s6-rc.d/go2rtc/run index 599ab887e4..56ef94e11c 100755 --- a/docker/main/rootfs/etc/s6-overlay/s6-rc.d/go2rtc/run +++ b/docker/main/rootfs/etc/s6-overlay/s6-rc.d/go2rtc/run @@ -110,6 +110,14 @@ fi readonly homekit_config_path="/config/go2rtc_homekit.yml" setup_homekit_config "${homekit_config_path}" +if [[ "$(id -u)" -eq 0 && "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then + chown go2rtc:go2rtc /dev/shm/go2rtc.yaml 2>/dev/null || true + # go2rtc rewrites this in place (os.WriteFile, no rename), so owning the + # file is enough; /config grants frigate-data traverse only + chown go2rtc:frigate-data "${homekit_config_path}" + chmod 664 "${homekit_config_path}" +fi + readonly config_path="/config" if [[ -x "${config_path}/go2rtc" ]]; then @@ -125,4 +133,8 @@ echo "[INFO] Starting go2rtc..." # Use HomeKit config as the primary config so writebacks go there # The main config from Frigate will be loaded as a secondary config exec 2>&1 -exec "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml +if [[ "$(id -u)" -ne 0 || "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then + exec "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml +else + exec s6-setuidgid go2rtc "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml +fi