fix(docker): refuse a root or non-numeric LOCAL_USER_ID

LOCAL_USER_ID=0 passed every check and reached `setpriv --reuid=0`: the bot would run root while looking properly configured, and useradd -o accepted the duplicate uid without complaint. A non-numeric value failed later inside useradd behind `|| true`, which hid the real cause. The entrypoint now rejects both up front with a message naming the variable, and the id/uid expansions are quoted so a value with spaces cannot word-split into extra useradd arguments (audit SEC-007).

Verified by sourcing the entrypoint under a faked `id`: uid 0, 'abc' and '12 3' each exit 1 with the refusal line, while a non-root caller passes straight through to exec. AGENTS and .env.example state the constraint.
This commit is contained in:
2026-09-24 15:12:22 +08:00
parent 4d6ec7924b
commit c420c95165
3 changed files with 24 additions and 6 deletions
+3 -1
View File
@@ -72,7 +72,9 @@ VIRTUAL_PORT=8443
DEFAULT_EMAIL=
# UID the container runs as; it must be able to write ./data on the host.
# The entrypoint's default (and the README's) is 9001 — keep them equal so
# the file owner on the host matches what you expect.
# the file owner on the host matches what you expect. Must be a non-zero
# numeric uid: the entrypoint refuses 0 (the bot would keep root through the
# privilege drop) and anything non-numeric.
LOCAL_USER_ID=9001
# Uncomment (here and the matching line in docker-compose.yml) to have
# acme-companion issue the certificate for VIRTUAL_HOST.