Skip to content

Commit 76bf7bf

Browse files
agarctficlaude
andauthored
fix(docker): add coreutils so MAX_LIFETIME_SECONDS works on Wolfi base (#586)
## Summary `MAX_LIFETIME_SECONDS` is broken on the published `unstructured-api` image and has been since the base image moved from RockyLinux to Chainguard Wolfi (#423). `scripts/app-start.sh` runs GNU `timeout` with `--preserve-status` and `--foreground` when `MAX_LIFETIME_SECONDS` is set. The Wolfi base only provides BusyBox `timeout`, which does not support those flags, so BusyBox rejects the first one and exits non-zero. uvicorn never launches, the script falls through to its shutdown echoes, and a container with a restart policy loops. GNU coreutils shipped for free as part of the old RockyLinux userland and was lost in the distro swap; it has never been an explicit package in the Dockerfile. This PR adds it back. Reported in Pylon 2657. Fixes ENG-1428. ## Reproduction Runs the real `scripts/app-start.sh` with a stub standing in for uvicorn. Current base (BusyBox `timeout`), server never starts: ``` $ docker run --rm -e MAX_LIFETIME_SECONDS=3 -v "$PWD:/work" \ --entrypoint sh cgr.dev/chainguard/wolfi-base:latest \ -c 'apk add --no-cache bash >/dev/null 2>&1; export PATH=/work/bin:$PATH; cd /work; bash app-start.sh' Server's lifetime set to 3 seconds. timeout: unrecognized option '--preserve-status' BusyBox v1.38.0 multi-call binary. Usage: timeout [-s SIG] [-k KILL_SECS] SECS PROG ARGS Server was shutdown Reached timeout of 3 seconds ``` The stub "server started" line never prints. With this fix (base + coreutils), server launches and runs for the full lifetime: ``` $ docker run --rm -e MAX_LIFETIME_SECONDS=3 -v "$PWD:/work" \ --entrypoint sh cgr.dev/chainguard/wolfi-base:latest \ -c 'apk add --no-cache bash coreutils >/dev/null 2>&1; export PATH=/work/bin:$PATH; cd /work; bash app-start.sh' Server's lifetime set to 3 seconds. [stub-uvicorn] server started, args: prepline_general.api.app:app --log-config logger_config.yaml --host 0.0.0.0 --port 8000 --workers 1 Server was shutdown Reached timeout of 3 seconds ``` ## CVE impact `apk add coreutils` was scanned with grype (DB 27 August 2026) on `cgr.dev/chainguard/wolfi-base:latest`: | Image | apk packages | CVEs | | --- | --- | --- | | base as-is | 15 | 0 | | base + coreutils | 21 | 0 | It pulls in 6 Chainguard-maintained packages (coreutils, libacl1, libattr1, libpcre2-8-0, libselinux, libsepol), all with no known vulnerabilities. Image size grows about 10 MB. Adding coreutils does not reintroduce the RockyLinux CVE surface that #423 was shedding. ## Notes - The guard in `app-start.sh` (`command -v timeout`) is also broken independent of the base image: BusyBox `timeout` satisfies the check, so the intended `gtimeout` fallback never runs. This PR fixes the reported bug by making GNU `timeout` present; hardening the script to detect BusyBox vs GNU would make it robust regardless of base and can be a follow-up. - The `core-product` mirror of this Dockerfile (base `cgr.dev/unstructured.io/python-fips:3.12-dev`) is also Wolfi-based and lacks coreutils, so it needs the same change. ## Test plan - [x] Reproduced the failure with the real `app-start.sh` on the current base - [x] Verified the server starts and runs for the full lifetime with coreutils - [x] Confirmed 0 new CVEs via grype Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 parent b887028 commit 76bf7bf

3 files changed

Lines changed: 8 additions & 2 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,9 @@
1+
## 0.1.11
2+
3+
### Fixes
4+
5+
- **Restore `MAX_LIFETIME_SECONDS` support in the Docker image**: `scripts/app-start.sh` invokes GNU `timeout` with `--preserve-status` and `--foreground`, flags the Wolfi base's BusyBox `timeout` does not support. Setting `MAX_LIFETIME_SECONDS` therefore caused the server to fail to start and the container to restart-loop. Added `coreutils` to the image so GNU `timeout` is available. This regressed when the base image moved from RockyLinux (which shipped GNU coreutils) to Wolfi.
6+
17
## 0.1.10
28

39
### Fixes

‎Dockerfile‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ USER root
1717

1818
RUN apk update && \
1919
apk add libxml2 python-3.12 python-3.12-base glib \
20-
mesa-gl mesa-libgallium cmake bash libmagic wget git openjpeg \
20+
mesa-gl mesa-libgallium cmake bash coreutils libmagic wget git openjpeg \
2121
poppler poppler-utils poppler-glib libreoffice tesseract && \
2222
git clone --depth 1 https://github.com/tesseract-ocr/tessdata.git /tmp/tessdata && \
2323
mkdir -p /usr/local/share/tessdata && \
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
__version__ = "0.1.10" # pragma: no cover
1+
__version__ = "0.1.11" # pragma: no cover

0 commit comments

Comments
 (0)