mirror of
https://github.com/blakeblackshear/frigate.git
synced 2026-10-03 05:16:50 +03:00
let services listed in FRIGATE_ROOT_SERVICES skip the privilege drop
This commit is contained in:
@@ -4,10 +4,18 @@
|
|||||||
|
|
||||||
set -o errexit -o nounset -o pipefail
|
set -o errexit -o nounset -o pipefail
|
||||||
|
|
||||||
|
runs_as_root=0
|
||||||
|
if [[ "$(id -u)" -eq 0 ]]; then
|
||||||
|
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]] || /usr/local/bin/service-runs-as-root frigate; then
|
||||||
|
runs_as_root=1
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
# $HOME is /root from the container env and survives s6-setuidgid, so cache
|
# $HOME is /root from the container env and survives s6-setuidgid, so cache
|
||||||
# and telemetry writes (huggingface, openvino) fail after the drop. Set it
|
# and telemetry writes (huggingface, openvino) fail after the drop. Set it
|
||||||
# before opt_in_out so the opt-out marker lands where the service will look.
|
# before opt_in_out so the opt-out marker lands where the service will look.
|
||||||
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then
|
# When the service keeps root, /root stays correct.
|
||||||
|
if [[ "$runs_as_root" -eq 0 ]]; then
|
||||||
export HOME=/config
|
export HOME=/config
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -37,7 +45,7 @@ cd /opt/frigate || echo "[ERROR] Failed to change working directory to /opt/frig
|
|||||||
|
|
||||||
# Replace the bash process with the Frigate process, redirecting stderr to stdout
|
# Replace the bash process with the Frigate process, redirecting stderr to stdout
|
||||||
exec 2>&1
|
exec 2>&1
|
||||||
if [[ "$(id -u)" -ne 0 || "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then
|
if [[ "$(id -u)" -ne 0 || "$runs_as_root" -eq 1 ]]; then
|
||||||
exec python3 -u -m frigate
|
exec python3 -u -m frigate
|
||||||
else
|
else
|
||||||
exec s6-setuidgid frigate python3 -u -m frigate
|
exec s6-setuidgid frigate python3 -u -m frigate
|
||||||
|
|||||||
@@ -4,6 +4,13 @@
|
|||||||
|
|
||||||
set -o errexit -o nounset -o pipefail
|
set -o errexit -o nounset -o pipefail
|
||||||
|
|
||||||
|
runs_as_root=0
|
||||||
|
if [[ "$(id -u)" -eq 0 ]]; then
|
||||||
|
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]] || /usr/local/bin/service-runs-as-root go2rtc; then
|
||||||
|
runs_as_root=1
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
# Logs should be sent to stdout so that s6 can collect them
|
# Logs should be sent to stdout so that s6 can collect them
|
||||||
|
|
||||||
function get_ip_and_port_from_supervisor() {
|
function get_ip_and_port_from_supervisor() {
|
||||||
@@ -110,7 +117,7 @@ fi
|
|||||||
readonly homekit_config_path="/config/go2rtc_homekit.yml"
|
readonly homekit_config_path="/config/go2rtc_homekit.yml"
|
||||||
setup_homekit_config "${homekit_config_path}"
|
setup_homekit_config "${homekit_config_path}"
|
||||||
|
|
||||||
if [[ "$(id -u)" -eq 0 && "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then
|
if [[ "$(id -u)" -eq 0 && "$runs_as_root" -eq 0 ]]; then
|
||||||
chown go2rtc:go2rtc /dev/shm/go2rtc.yaml 2>/dev/null || true
|
chown go2rtc:go2rtc /dev/shm/go2rtc.yaml 2>/dev/null || true
|
||||||
# go2rtc rewrites this in place (os.WriteFile, no rename), so owning the
|
# go2rtc rewrites this in place (os.WriteFile, no rename), so owning the
|
||||||
# file is enough; /config grants frigate-data traverse only. Tolerated so
|
# file is enough; /config grants frigate-data traverse only. Tolerated so
|
||||||
@@ -135,7 +142,7 @@ echo "[INFO] Starting go2rtc..."
|
|||||||
# Use HomeKit config as the primary config so writebacks go there
|
# Use HomeKit config as the primary config so writebacks go there
|
||||||
# The main config from Frigate will be loaded as a secondary config
|
# The main config from Frigate will be loaded as a secondary config
|
||||||
exec 2>&1
|
exec 2>&1
|
||||||
if [[ "$(id -u)" -ne 0 || "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then
|
if [[ "$(id -u)" -ne 0 || "$runs_as_root" -eq 1 ]]; then
|
||||||
exec "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml
|
exec "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml
|
||||||
else
|
else
|
||||||
exec s6-setuidgid go2rtc "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml
|
exec s6-setuidgid go2rtc "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml
|
||||||
|
|||||||
@@ -4,6 +4,13 @@
|
|||||||
|
|
||||||
set -o errexit -o nounset -o pipefail
|
set -o errexit -o nounset -o pipefail
|
||||||
|
|
||||||
|
runs_as_root=0
|
||||||
|
if [[ "$(id -u)" -eq 0 ]]; then
|
||||||
|
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]] || /usr/local/bin/service-runs-as-root nginx; then
|
||||||
|
runs_as_root=1
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
# Logs should be sent to stdout so that s6 can collect them
|
# Logs should be sent to stdout so that s6 can collect them
|
||||||
|
|
||||||
echo "[INFO] Starting NGINX..."
|
echo "[INFO] Starting NGINX..."
|
||||||
@@ -104,7 +111,7 @@ echo "$nginx_settings" | \
|
|||||||
tempio -template /usr/local/nginx/templates/listen.gotmpl \
|
tempio -template /usr/local/nginx/templates/listen.gotmpl \
|
||||||
-out /tmp/nginx/conf/listen.conf
|
-out /tmp/nginx/conf/listen.conf
|
||||||
|
|
||||||
if [[ "$(id -u)" -eq 0 && "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then
|
if [[ "$(id -u)" -eq 0 && "$runs_as_root" -eq 0 ]]; then
|
||||||
chown -R frigate:frigate /tmp/nginx
|
chown -R frigate:frigate /tmp/nginx
|
||||||
# heal the cache if a root `nginx -t` chowned it (ngx_create_paths chowns
|
# heal the cache if a root `nginx -t` chowned it (ngx_create_paths chowns
|
||||||
# every cycle path to the `user` directive user when run as root)
|
# every cycle path to the `user` directive user when run as root)
|
||||||
@@ -125,7 +132,7 @@ fi
|
|||||||
exec 2>&1
|
exec 2>&1
|
||||||
# -e stderr: the compile-time default error log under /usr/local/nginx/logs
|
# -e stderr: the compile-time default error log under /usr/local/nginx/logs
|
||||||
# is not writable by the runtime user and would alert before config load
|
# is not writable by the runtime user and would alert before config load
|
||||||
if [[ "$(id -u)" -ne 0 || "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then
|
if [[ "$(id -u)" -ne 0 || "$runs_as_root" -eq 1 ]]; then
|
||||||
exec \
|
exec \
|
||||||
s6-notifyoncheck -t 30000 -n 1 \
|
s6-notifyoncheck -t 30000 -n 1 \
|
||||||
nginx -e stderr -c /tmp/nginx/conf/nginx.conf
|
nginx -e stderr -c /tmp/nginx/conf/nginx.conf
|
||||||
|
|||||||
Reference in New Issue
Block a user