From e0ae2ec49c8648804976bec897b608880bee847f Mon Sep 17 00:00:00 2001 From: Swarna Sekhar Dhar <3263074+methakon@users.noreply.github.com> Date: Mon, 28 Sep 2026 17:23:30 +0530 Subject: [PATCH] fix: skip the vendor tree when fixing permissions on startup Every start chowns the whole vendor tree (~13k files) when a custom PUID/PGID is used. Those files live in the image layer, so each chown copies the file up, delaying startup for 90s on fast disks and up to hours on slow or network storage (#524, #557). The find introduced in #540 cannot help here: a freshly created container always starts with the build-time ownership, so the tree needs fixing again every time. The vendor tree and the composer files are dropped from the runtime permission fix and made writable for any uid during the build instead (they are only written by plugin/composer installs). All other paths keep their ownership fix. Fixes #557 --- Dockerfile | 5 +++++ rootfs/etc/cont-init.d/03-config.sh | 5 ++++- 2 files changed, 9 insertions(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index f20d98f5..22bac201 100644 --- a/Dockerfile +++ b/Dockerfile @@ -133,6 +133,11 @@ RUN apk --update --no-cache add -t build-dependencies \ && echo "foreach (glob(\"${LIBRENMS_PATH}/config.d/*.php\") as \$filename) include \$filename;" >> config.php \ && chown -R librenms:librenms ${LIBRENMS_PATH} \ && su librenms -s /bin/sh -c "COMPOSER_CACHE_DIR=/tmp composer install --no-dev --no-interaction --no-ansi" \ + # vendor and composer files are only written by plugin/composer installs, and the container + # commonly runs under a custom PUID/PGID - the runtime permission fix intentionally skips + # them for that reason (https://github.com/librenms/docker/issues/557), so make them writable here + && chmod -R a+rwX vendor \ + && chmod a+rw composer.json composer.lock \ && apk del build-dependencies \ && rm -rf .git \ html/plugins/Test \ diff --git a/rootfs/etc/cont-init.d/03-config.sh b/rootfs/etc/cont-init.d/03-config.sh index 5b02a259..82358605 100644 --- a/rootfs/etc/cont-init.d/03-config.sh +++ b/rootfs/etc/cont-init.d/03-config.sh @@ -217,9 +217,12 @@ for plugin in ${plugins}; do done # Fix perms +# the vendor tree and composer files are not chowned below: chowning the ~13k vendor files +# delays every start with custom PUID/PGID (https://github.com/librenms/docker/issues/557) and +# is only needed for plugin/composer installs, for which the image build sets write permissions echo "Fixing perms..." chown librenms:librenms /data/config /data/monitoring-plugins /data/plugins /data/rrd /data/weathermap /data/alert-templates -find /data/logs ${LIBRENMS_PATH}/composer* ${LIBRENMS_PATH}/config.d ${LIBRENMS_PATH}/bootstrap ${LIBRENMS_PATH}/logs ${LIBRENMS_PATH}/storage ${LIBRENMS_PATH}/vendor \( ! -user librenms -o ! -group librenms \) -exec chown librenms:librenms {} + +find /data/logs ${LIBRENMS_PATH}/config.d ${LIBRENMS_PATH}/bootstrap ${LIBRENMS_PATH}/logs ${LIBRENMS_PATH}/storage \( ! -user librenms -o ! -group librenms \) -exec chown librenms:librenms {} + chmod ug+rw /data/logs /data/rrd ${LIBRENMS_PATH}/bootstrap/cache ${LIBRENMS_PATH}/storage ${LIBRENMS_PATH}/storage/framework/* # Check additional Monitoring plugins