git: a4cf63265766 - main - www/immich: Fix immich-admin for any login shell
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 23 Sep 2026 11:51:19 UTC
The branch main has been updated by joneum:
URL: https://cgit.FreeBSD.org/ports/commit/?id=a4cf632657665c61130f2650c269eebddc8cfd4c
commit a4cf632657665c61130f2650c269eebddc8cfd4c
Author: Jochen Neumeister <joneum@FreeBSD.org>
AuthorDate: 2026-09-23 11:50:46 +0000
Commit: Jochen Neumeister <joneum@FreeBSD.org>
CommitDate: 2026-09-23 11:51:11 +0000
www/immich: Fix immich-admin for any login shell
su -m runs the command in the caller's login shell, so the wrapper
broke wherever root does not use a POSIX shell. chroot(8) drops the
privileges without a shell in between and passes the arguments to
execve(2) unchanged.
Reported by: mfechner
Sponsored by: Netzkommune GmbH
---
www/immich/files/immich-admin.in | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/www/immich/files/immich-admin.in b/www/immich/files/immich-admin.in
index fbf57042bbc4..bcc0aa802130 100644
--- a/www/immich/files/immich-admin.in
+++ b/www/immich/files/immich-admin.in
@@ -27,8 +27,11 @@ export IMMICH_BUILD_DATA=%%WWWDIR%%/build-data
export NODE_ENV=production
if [ "$(id -u)" = "0" ]; then
- exec su -m immich -c 'exec %%LOCALBASE%%/bin/node --no-warnings "$0" immich-admin "$@"' \
- "${MAIN}" "$@"
+ # chroot(8) drops privileges without a shell in between, so the
+ # arguments reach execve(2) untouched no matter what the caller's
+ # login shell is.
+ exec chroot -u immich -g immich / %%LOCALBASE%%/bin/node --no-warnings \
+ "${MAIN}" immich-admin "$@"
fi
exec %%LOCALBASE%%/bin/node --no-warnings "${MAIN}" immich-admin "$@"