Spaces:
Paused
Paused
Update Dockerfile
Browse files- Dockerfile +118 -9
Dockerfile
CHANGED
|
@@ -7,10 +7,14 @@ RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
| 7 |
|
| 8 |
WORKDIR /app
|
| 9 |
|
| 10 |
-
ARG LUMIVERSE_REPO=https://github.com/
|
| 11 |
-
ARG LUMIVERSE_REF=
|
| 12 |
RUN git clone --depth 1 --branch "${LUMIVERSE_REF}" "${LUMIVERSE_REPO}" .
|
| 13 |
|
|
|
|
|
|
|
|
|
|
|
|
|
| 14 |
RUN cat > /tmp/patch-auth-rewrite.mjs <<'PATCH'
|
| 15 |
import { readFileSync, writeFileSync } from "fs";
|
| 16 |
|
|
@@ -39,17 +43,23 @@ const after = `app.on(["POST", "GET"], "/api/auth/*", (c) => {
|
|
| 39 |
return auth.handler(c.req.raw);
|
| 40 |
});`;
|
| 41 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 42 |
if (!src.includes(before)) {
|
| 43 |
-
console.
|
| 44 |
-
|
|
|
|
|
|
|
| 45 |
}
|
| 46 |
|
| 47 |
writeFileSync(path, src.replace(before, after), "utf8");
|
| 48 |
console.log("[patch] Patched src/app.ts for x-forwarded-proto/host");
|
| 49 |
PATCH
|
| 50 |
|
| 51 |
-
RUN bun /tmp/patch-auth-rewrite.mjs
|
| 52 |
-
&& grep -n "x-forwarded-proto" src/app.ts >/dev/null
|
| 53 |
|
| 54 |
RUN rm -f package-lock.json && bun install --production
|
| 55 |
|
|
@@ -64,23 +74,122 @@ ENV PORT=7860
|
|
| 64 |
ENV DATA_DIR=/app/data
|
| 65 |
ENV FRONTEND_DIR=/app/frontend/dist
|
| 66 |
ENV TRUST_ANY_ORIGIN=true
|
| 67 |
-
ENV OWNER_PASSWORD=
|
| 68 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 69 |
RUN cat > /app/start.sh <<'SH'
|
| 70 |
#!/usr/bin/env sh
|
| 71 |
set -eu
|
| 72 |
-
|
| 73 |
export DATA_DIR="${DATA_DIR:-/app/data}"
|
| 74 |
|
| 75 |
-
# Run
|
|
|
|
|
|
|
|
|
|
| 76 |
exec bun run scripts/runner.ts
|
| 77 |
SH
|
| 78 |
|
| 79 |
RUN chmod +x /app/start.sh
|
| 80 |
|
| 81 |
USER root
|
|
|
|
| 82 |
RUN mkdir -p /app/data && chown -R bun:bun /app/data
|
| 83 |
|
|
|
|
|
|
|
|
|
|
| 84 |
EXPOSE 7860
|
| 85 |
VOLUME /app/data
|
| 86 |
|
|
|
|
| 7 |
|
| 8 |
WORKDIR /app
|
| 9 |
|
| 10 |
+
ARG LUMIVERSE_REPO=https://github.com/CloudCompile/Lumiverse.git
|
| 11 |
+
ARG LUMIVERSE_REF=Leaderboard
|
| 12 |
RUN git clone --depth 1 --branch "${LUMIVERSE_REF}" "${LUMIVERSE_REPO}" .
|
| 13 |
|
| 14 |
+
# This patch only applies to forks/branches that still have the old
|
| 15 |
+
# unpatched host-only rewrite block. If the fork has already diverged
|
| 16 |
+
# (different code, or already fixed upstream), the patch is skipped
|
| 17 |
+
# instead of failing the whole build.
|
| 18 |
RUN cat > /tmp/patch-auth-rewrite.mjs <<'PATCH'
|
| 19 |
import { readFileSync, writeFileSync } from "fs";
|
| 20 |
|
|
|
|
| 43 |
return auth.handler(c.req.raw);
|
| 44 |
});`;
|
| 45 |
|
| 46 |
+
if (src.includes("x-forwarded-host") || src.includes("x-forwarded-proto")) {
|
| 47 |
+
console.log("[patch] src/app.ts already forwards x-forwarded-host/proto — skipping patch");
|
| 48 |
+
process.exit(0);
|
| 49 |
+
}
|
| 50 |
+
|
| 51 |
if (!src.includes(before)) {
|
| 52 |
+
console.warn("[patch] Expected auth rewrite block not found in src/app.ts — skipping patch");
|
| 53 |
+
console.warn("[patch] This fork/branch may have a different auth setup. If HTTPS auth redirects");
|
| 54 |
+
console.warn("[patch] fail at runtime, this file will need a manual patch.");
|
| 55 |
+
process.exit(0);
|
| 56 |
}
|
| 57 |
|
| 58 |
writeFileSync(path, src.replace(before, after), "utf8");
|
| 59 |
console.log("[patch] Patched src/app.ts for x-forwarded-proto/host");
|
| 60 |
PATCH
|
| 61 |
|
| 62 |
+
RUN bun /tmp/patch-auth-rewrite.mjs
|
|
|
|
| 63 |
|
| 64 |
RUN rm -f package-lock.json && bun install --production
|
| 65 |
|
|
|
|
| 74 |
ENV DATA_DIR=/app/data
|
| 75 |
ENV FRONTEND_DIR=/app/frontend/dist
|
| 76 |
ENV TRUST_ANY_ORIGIN=true
|
| 77 |
+
ENV OWNER_PASSWORD=admin123
|
| 78 |
|
| 79 |
+
# === DATA INTEGRITY & CORRUPTION RECOVERY ===
|
| 80 |
+
# Create a recovery script that runs before the app starts
|
| 81 |
+
RUN cat > /app/check-and-repair-data.sh <<'REPAIR'
|
| 82 |
+
#!/usr/bin/env sh
|
| 83 |
+
set -e
|
| 84 |
+
|
| 85 |
+
DATA_DIR="${DATA_DIR:-/app/data}"
|
| 86 |
+
|
| 87 |
+
echo "[integrity] Starting pre-startup data checks..."
|
| 88 |
+
|
| 89 |
+
# Ensure data directory structure exists
|
| 90 |
+
mkdir -p "$DATA_DIR"
|
| 91 |
+
|
| 92 |
+
# Critical check: top-level entries (users, uploads, extensions) must be
|
| 93 |
+
# directories. HF Spaces storage remounts have been observed to leave these
|
| 94 |
+
# as stray files instead. If any of them is a file, quarantine it before
|
| 95 |
+
# trying to mkdir, or every startup will fail with "File exists".
|
| 96 |
+
for entry in users uploads extensions; do
|
| 97 |
+
entry_path="$DATA_DIR/$entry"
|
| 98 |
+
if [ -e "$entry_path" ] && [ ! -d "$entry_path" ]; then
|
| 99 |
+
echo "[integrity] $entry_path exists but is not a directory (corrupted remount)"
|
| 100 |
+
echo "[integrity] Quarantining to ${entry_path}.corrupted-$(date +%s)"
|
| 101 |
+
mv "$entry_path" "${entry_path}.corrupted-$(date +%s)"
|
| 102 |
+
fi
|
| 103 |
+
done
|
| 104 |
+
|
| 105 |
+
USERS_DIR="$DATA_DIR/users"
|
| 106 |
+
|
| 107 |
+
# If users directory exists, scan for corrupted entries
|
| 108 |
+
if [ -d "$USERS_DIR" ]; then
|
| 109 |
+
echo "[integrity] Checking user directories for corruption..."
|
| 110 |
+
|
| 111 |
+
find "$USERS_DIR" -maxdepth 1 -type f 2>/dev/null | while read -r corrupt_file; do
|
| 112 |
+
# There should be NO files directly in users/ — only directories
|
| 113 |
+
echo "[integrity] Found stray file in users/: $corrupt_file"
|
| 114 |
+
echo "[integrity] Moving to quarantine: ${corrupt_file}.corrupted"
|
| 115 |
+
mv "$corrupt_file" "${corrupt_file}.corrupted"
|
| 116 |
+
done
|
| 117 |
+
|
| 118 |
+
# Check each user's subdirectory for storage file/directory collision
|
| 119 |
+
find "$USERS_DIR" -maxdepth 2 -name "storage" -type f 2>/dev/null | while read -r storage_file; do
|
| 120 |
+
user_dir=$(dirname "$storage_file")
|
| 121 |
+
echo "[integrity] Found file where directory expected: $storage_file"
|
| 122 |
+
echo "[integrity] This was caused by HF Spaces storage remount. Removing corrupt file..."
|
| 123 |
+
rm -f "$storage_file"
|
| 124 |
+
echo "[integrity] Directory will be auto-created on first use"
|
| 125 |
+
done
|
| 126 |
+
fi
|
| 127 |
+
|
| 128 |
+
# Pre-create critical directories to prevent race conditions.
|
| 129 |
+
# These run with '|| true' as a last-resort safety net: the loop above should
|
| 130 |
+
# have already cleared any file/directory collisions, but if something
|
| 131 |
+
# unexpected still blocks mkdir, log it instead of crashing the container —
|
| 132 |
+
# the app's own provisioning code can then surface a clearer error.
|
| 133 |
+
mkdir -p "$DATA_DIR/users" || echo "[integrity] WARNING: could not create $DATA_DIR/users, check manually"
|
| 134 |
+
mkdir -p "$DATA_DIR/uploads" || echo "[integrity] WARNING: could not create $DATA_DIR/uploads, check manually"
|
| 135 |
+
mkdir -p "$DATA_DIR/extensions" || echo "[integrity] WARNING: could not create $DATA_DIR/extensions, check manually"
|
| 136 |
+
|
| 137 |
+
# Verify SQLite database integrity if it exists
|
| 138 |
+
DB_PATH="$DATA_DIR/lumiverse.db"
|
| 139 |
+
if [ -e "$DB_PATH" ]; then
|
| 140 |
+
echo "[integrity] Inspecting $DB_PATH..."
|
| 141 |
+
ls -la "$DB_PATH" 2>&1 || true
|
| 142 |
+
file "$DB_PATH" 2>&1 || true
|
| 143 |
+
|
| 144 |
+
if [ ! -f "$DB_PATH" ]; then
|
| 145 |
+
echo "[integrity] $DB_PATH exists but is not a regular file (corrupted remount)"
|
| 146 |
+
echo "[integrity] Quarantining to ${DB_PATH}.corrupted-$(date +%s)"
|
| 147 |
+
mv "$DB_PATH" "${DB_PATH}.corrupted-$(date +%s)"
|
| 148 |
+
else
|
| 149 |
+
echo "[integrity] Running SQLite integrity check..."
|
| 150 |
+
if ! sqlite3 "$DB_PATH" "PRAGMA integrity_check;" 2>&1 | grep -q "ok"; then
|
| 151 |
+
echo "[integrity] WARNING: Database integrity check failed (disk I/O error or corruption)."
|
| 152 |
+
echo "[integrity] NOT deleting or overwriting the database automatically — that risks data loss."
|
| 153 |
+
echo "[integrity] Backing up as-is to ${DB_PATH}.bak-$(date +%s) for manual inspection."
|
| 154 |
+
cp "$DB_PATH" "${DB_PATH}.bak-$(date +%s)" 2>&1 || echo "[integrity] Backup copy also failed — underlying mount may be unhealthy."
|
| 155 |
+
echo "[integrity] The app will attempt to start anyway; if it cannot open the database,"
|
| 156 |
+
echo "[integrity] this usually means the persistent storage mount itself needs to be"
|
| 157 |
+
echo "[integrity] detached and reattached from the Space's Settings page."
|
| 158 |
+
else
|
| 159 |
+
echo "[integrity] Database integrity check passed"
|
| 160 |
+
fi
|
| 161 |
+
fi
|
| 162 |
+
else
|
| 163 |
+
echo "[integrity] No existing database found at $DB_PATH (fresh install or not yet created)"
|
| 164 |
+
fi
|
| 165 |
+
|
| 166 |
+
echo "[integrity] Pre-startup checks complete"
|
| 167 |
+
REPAIR
|
| 168 |
+
|
| 169 |
+
RUN chmod +x /app/check-and-repair-data.sh
|
| 170 |
+
|
| 171 |
+
# Startup script that runs integrity check BEFORE the app
|
| 172 |
RUN cat > /app/start.sh <<'SH'
|
| 173 |
#!/usr/bin/env sh
|
| 174 |
set -eu
|
|
|
|
| 175 |
export DATA_DIR="${DATA_DIR:-/app/data}"
|
| 176 |
|
| 177 |
+
# Run data integrity checks first
|
| 178 |
+
/app/check-and-repair-data.sh
|
| 179 |
+
|
| 180 |
+
# Then start the app
|
| 181 |
exec bun run scripts/runner.ts
|
| 182 |
SH
|
| 183 |
|
| 184 |
RUN chmod +x /app/start.sh
|
| 185 |
|
| 186 |
USER root
|
| 187 |
+
# Create data directory with proper permissions
|
| 188 |
RUN mkdir -p /app/data && chown -R bun:bun /app/data
|
| 189 |
|
| 190 |
+
# Pre-create user directory to prevent first-run permission issues
|
| 191 |
+
RUN mkdir -p /app/data/users && chown -R bun:bun /app/data/users
|
| 192 |
+
|
| 193 |
EXPOSE 7860
|
| 194 |
VOLUME /app/data
|
| 195 |
|