tolerate homekit config chown failures in the go2rtc run script

This commit is contained in:
Josh Hawkins
2026-08-27 07:47:58 -05:00
parent 9def198180
commit 88ff2dd9e8
2 changed files with 6 additions and 4 deletions
@@ -113,9 +113,11 @@ setup_homekit_config "${homekit_config_path}"
if [[ "$(id -u)" -eq 0 && "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then
chown go2rtc:go2rtc /dev/shm/go2rtc.yaml 2>/dev/null || true
# go2rtc rewrites this in place (os.WriteFile, no rename), so owning the
# file is enough; /config grants frigate-data traverse only
chown go2rtc:frigate-data "${homekit_config_path}"
chmod 664 "${homekit_config_path}"
# file is enough; /config grants frigate-data traverse only. Tolerated so
# a chown-refusing mount (NFS root_squash) degrades pairing persistence
# instead of crash-looping the service
chown go2rtc:frigate-data "${homekit_config_path}" 2>/dev/null && chmod 664 "${homekit_config_path}" 2>/dev/null || \
echo "[WARN] Could not hand ${homekit_config_path} to the go2rtc user; HomeKit pairing changes may not persist"
fi
readonly config_path="/config"
@@ -100,7 +100,7 @@ echo "$nginx_settings" | \
if [[ "$(id -u)" -eq 0 && "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then
chown -R frigate:frigate /tmp/nginx
# only the self-signed key we just generated; user-mounted certs may be :ro
# self-signed certs are root-generated; tolerant because mounted certs may be :ro
if [ -f "$letsencrypt_path/privkey.pem" ]; then
chown frigate:frigate "$letsencrypt_path/privkey.pem" "$letsencrypt_path/fullchain.pem" 2>/dev/null || true
fi