From dda3730a764e72d5c8ff482b1880e2aa3c1dbbae Mon Sep 17 00:00:00 2001 From: Josh Hawkins <32435876+hawkeye217@users.noreply.github.com> Date: Thu, 27 Aug 2026 12:26:39 -0500 Subject: [PATCH] add a service-runs-as-root helper for granular root services --- .../rootfs/usr/local/bin/service-runs-as-root | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) create mode 100755 docker/main/rootfs/usr/local/bin/service-runs-as-root diff --git a/docker/main/rootfs/usr/local/bin/service-runs-as-root b/docker/main/rootfs/usr/local/bin/service-runs-as-root new file mode 100755 index 0000000000..69944cb7d8 --- /dev/null +++ b/docker/main/rootfs/usr/local/bin/service-runs-as-root @@ -0,0 +1,19 @@ +#!/bin/bash +# Exit 0 when FRIGATE_ROOT_SERVICES names the given service. +# Membership only: FRIGATE_RUN_AS_ROOT precedence and the euid check stay in +# the callers, which each combine them differently. +# +# Usage: service-runs-as-root SERVICE + +set -o nounset + +service="${1:?usage: service-runs-as-root SERVICE}" + +IFS=',' read -ra entries <<< "${FRIGATE_ROOT_SERVICES:-}" +for entry in "${entries[@]}"; do + entry="${entry//[[:space:]]/}" + if [[ "$entry" == "$service" ]]; then + exit 0 + fi +done +exit 1