looking at the code for entrypoint.js, it seems as though the process.setuid() call is inside the if clause that checks to see if the host user exists in the docker container.
I think this means that the process will run as root if the user aleady exists, so we should probably move the setuid() call outside of that if clause, i.e.:
looking at the code for
entrypoint.js
, it seems as though theprocess.setuid()
call is inside theif
clause that checks to see if the host user exists in the docker container.I think this means that the process will run as
root
if the user aleady exists, so we should probably move thesetuid()
call outside of thatif
clause, i.e.: