CJHauser commited on
Commit
3d64dad
·
verified ·
1 Parent(s): e7e17e2

Update Dockerfile

Browse files
Files changed (1) hide show
  1. Dockerfile +118 -9
Dockerfile CHANGED
@@ -7,10 +7,14 @@ RUN apt-get update && apt-get install -y --no-install-recommends \
7
 
8
  WORKDIR /app
9
 
10
- ARG LUMIVERSE_REPO=https://github.com/prolix-oc/Lumiverse.git
11
- ARG LUMIVERSE_REF=staging
12
  RUN git clone --depth 1 --branch "${LUMIVERSE_REF}" "${LUMIVERSE_REPO}" .
13
 
 
 
 
 
14
  RUN cat > /tmp/patch-auth-rewrite.mjs <<'PATCH'
15
  import { readFileSync, writeFileSync } from "fs";
16
 
@@ -39,17 +43,23 @@ const after = `app.on(["POST", "GET"], "/api/auth/*", (c) => {
39
  return auth.handler(c.req.raw);
40
  });`;
41
 
 
 
 
 
 
42
  if (!src.includes(before)) {
43
- console.error("[patch] Expected auth rewrite block not found in src/app.ts");
44
- process.exit(1);
 
 
45
  }
46
 
47
  writeFileSync(path, src.replace(before, after), "utf8");
48
  console.log("[patch] Patched src/app.ts for x-forwarded-proto/host");
49
  PATCH
50
 
51
- RUN bun /tmp/patch-auth-rewrite.mjs \
52
- && grep -n "x-forwarded-proto" src/app.ts >/dev/null
53
 
54
  RUN rm -f package-lock.json && bun install --production
55
 
@@ -64,23 +74,122 @@ ENV PORT=7860
64
  ENV DATA_DIR=/app/data
65
  ENV FRONTEND_DIR=/app/frontend/dist
66
  ENV TRUST_ANY_ORIGIN=true
67
- ENV OWNER_PASSWORD="admin123admin"
68
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
69
  RUN cat > /app/start.sh <<'SH'
70
  #!/usr/bin/env sh
71
  set -eu
72
-
73
  export DATA_DIR="${DATA_DIR:-/app/data}"
74
 
75
- # Run with the runner script so IPC is available for the operator page
 
 
 
76
  exec bun run scripts/runner.ts
77
  SH
78
 
79
  RUN chmod +x /app/start.sh
80
 
81
  USER root
 
82
  RUN mkdir -p /app/data && chown -R bun:bun /app/data
83
 
 
 
 
84
  EXPOSE 7860
85
  VOLUME /app/data
86
 
 
7
 
8
  WORKDIR /app
9
 
10
+ ARG LUMIVERSE_REPO=https://github.com/CloudCompile/Lumiverse.git
11
+ ARG LUMIVERSE_REF=Leaderboard
12
  RUN git clone --depth 1 --branch "${LUMIVERSE_REF}" "${LUMIVERSE_REPO}" .
13
 
14
+ # This patch only applies to forks/branches that still have the old
15
+ # unpatched host-only rewrite block. If the fork has already diverged
16
+ # (different code, or already fixed upstream), the patch is skipped
17
+ # instead of failing the whole build.
18
  RUN cat > /tmp/patch-auth-rewrite.mjs <<'PATCH'
19
  import { readFileSync, writeFileSync } from "fs";
20
 
 
43
  return auth.handler(c.req.raw);
44
  });`;
45
 
46
+ if (src.includes("x-forwarded-host") || src.includes("x-forwarded-proto")) {
47
+ console.log("[patch] src/app.ts already forwards x-forwarded-host/proto — skipping patch");
48
+ process.exit(0);
49
+ }
50
+
51
  if (!src.includes(before)) {
52
+ console.warn("[patch] Expected auth rewrite block not found in src/app.ts — skipping patch");
53
+ console.warn("[patch] This fork/branch may have a different auth setup. If HTTPS auth redirects");
54
+ console.warn("[patch] fail at runtime, this file will need a manual patch.");
55
+ process.exit(0);
56
  }
57
 
58
  writeFileSync(path, src.replace(before, after), "utf8");
59
  console.log("[patch] Patched src/app.ts for x-forwarded-proto/host");
60
  PATCH
61
 
62
+ RUN bun /tmp/patch-auth-rewrite.mjs
 
63
 
64
  RUN rm -f package-lock.json && bun install --production
65
 
 
74
  ENV DATA_DIR=/app/data
75
  ENV FRONTEND_DIR=/app/frontend/dist
76
  ENV TRUST_ANY_ORIGIN=true
77
+ ENV OWNER_PASSWORD=admin123
78
 
79
+ # === DATA INTEGRITY & CORRUPTION RECOVERY ===
80
+ # Create a recovery script that runs before the app starts
81
+ RUN cat > /app/check-and-repair-data.sh <<'REPAIR'
82
+ #!/usr/bin/env sh
83
+ set -e
84
+
85
+ DATA_DIR="${DATA_DIR:-/app/data}"
86
+
87
+ echo "[integrity] Starting pre-startup data checks..."
88
+
89
+ # Ensure data directory structure exists
90
+ mkdir -p "$DATA_DIR"
91
+
92
+ # Critical check: top-level entries (users, uploads, extensions) must be
93
+ # directories. HF Spaces storage remounts have been observed to leave these
94
+ # as stray files instead. If any of them is a file, quarantine it before
95
+ # trying to mkdir, or every startup will fail with "File exists".
96
+ for entry in users uploads extensions; do
97
+ entry_path="$DATA_DIR/$entry"
98
+ if [ -e "$entry_path" ] && [ ! -d "$entry_path" ]; then
99
+ echo "[integrity] $entry_path exists but is not a directory (corrupted remount)"
100
+ echo "[integrity] Quarantining to ${entry_path}.corrupted-$(date +%s)"
101
+ mv "$entry_path" "${entry_path}.corrupted-$(date +%s)"
102
+ fi
103
+ done
104
+
105
+ USERS_DIR="$DATA_DIR/users"
106
+
107
+ # If users directory exists, scan for corrupted entries
108
+ if [ -d "$USERS_DIR" ]; then
109
+ echo "[integrity] Checking user directories for corruption..."
110
+
111
+ find "$USERS_DIR" -maxdepth 1 -type f 2>/dev/null | while read -r corrupt_file; do
112
+ # There should be NO files directly in users/ — only directories
113
+ echo "[integrity] Found stray file in users/: $corrupt_file"
114
+ echo "[integrity] Moving to quarantine: ${corrupt_file}.corrupted"
115
+ mv "$corrupt_file" "${corrupt_file}.corrupted"
116
+ done
117
+
118
+ # Check each user's subdirectory for storage file/directory collision
119
+ find "$USERS_DIR" -maxdepth 2 -name "storage" -type f 2>/dev/null | while read -r storage_file; do
120
+ user_dir=$(dirname "$storage_file")
121
+ echo "[integrity] Found file where directory expected: $storage_file"
122
+ echo "[integrity] This was caused by HF Spaces storage remount. Removing corrupt file..."
123
+ rm -f "$storage_file"
124
+ echo "[integrity] Directory will be auto-created on first use"
125
+ done
126
+ fi
127
+
128
+ # Pre-create critical directories to prevent race conditions.
129
+ # These run with '|| true' as a last-resort safety net: the loop above should
130
+ # have already cleared any file/directory collisions, but if something
131
+ # unexpected still blocks mkdir, log it instead of crashing the container —
132
+ # the app's own provisioning code can then surface a clearer error.
133
+ mkdir -p "$DATA_DIR/users" || echo "[integrity] WARNING: could not create $DATA_DIR/users, check manually"
134
+ mkdir -p "$DATA_DIR/uploads" || echo "[integrity] WARNING: could not create $DATA_DIR/uploads, check manually"
135
+ mkdir -p "$DATA_DIR/extensions" || echo "[integrity] WARNING: could not create $DATA_DIR/extensions, check manually"
136
+
137
+ # Verify SQLite database integrity if it exists
138
+ DB_PATH="$DATA_DIR/lumiverse.db"
139
+ if [ -e "$DB_PATH" ]; then
140
+ echo "[integrity] Inspecting $DB_PATH..."
141
+ ls -la "$DB_PATH" 2>&1 || true
142
+ file "$DB_PATH" 2>&1 || true
143
+
144
+ if [ ! -f "$DB_PATH" ]; then
145
+ echo "[integrity] $DB_PATH exists but is not a regular file (corrupted remount)"
146
+ echo "[integrity] Quarantining to ${DB_PATH}.corrupted-$(date +%s)"
147
+ mv "$DB_PATH" "${DB_PATH}.corrupted-$(date +%s)"
148
+ else
149
+ echo "[integrity] Running SQLite integrity check..."
150
+ if ! sqlite3 "$DB_PATH" "PRAGMA integrity_check;" 2>&1 | grep -q "ok"; then
151
+ echo "[integrity] WARNING: Database integrity check failed (disk I/O error or corruption)."
152
+ echo "[integrity] NOT deleting or overwriting the database automatically — that risks data loss."
153
+ echo "[integrity] Backing up as-is to ${DB_PATH}.bak-$(date +%s) for manual inspection."
154
+ cp "$DB_PATH" "${DB_PATH}.bak-$(date +%s)" 2>&1 || echo "[integrity] Backup copy also failed — underlying mount may be unhealthy."
155
+ echo "[integrity] The app will attempt to start anyway; if it cannot open the database,"
156
+ echo "[integrity] this usually means the persistent storage mount itself needs to be"
157
+ echo "[integrity] detached and reattached from the Space's Settings page."
158
+ else
159
+ echo "[integrity] Database integrity check passed"
160
+ fi
161
+ fi
162
+ else
163
+ echo "[integrity] No existing database found at $DB_PATH (fresh install or not yet created)"
164
+ fi
165
+
166
+ echo "[integrity] Pre-startup checks complete"
167
+ REPAIR
168
+
169
+ RUN chmod +x /app/check-and-repair-data.sh
170
+
171
+ # Startup script that runs integrity check BEFORE the app
172
  RUN cat > /app/start.sh <<'SH'
173
  #!/usr/bin/env sh
174
  set -eu
 
175
  export DATA_DIR="${DATA_DIR:-/app/data}"
176
 
177
+ # Run data integrity checks first
178
+ /app/check-and-repair-data.sh
179
+
180
+ # Then start the app
181
  exec bun run scripts/runner.ts
182
  SH
183
 
184
  RUN chmod +x /app/start.sh
185
 
186
  USER root
187
+ # Create data directory with proper permissions
188
  RUN mkdir -p /app/data && chown -R bun:bun /app/data
189
 
190
+ # Pre-create user directory to prevent first-run permission issues
191
+ RUN mkdir -p /app/data/users && chown -R bun:bun /app/data/users
192
+
193
  EXPOSE 7860
194
  VOLUME /app/data
195