#!/bin/sh # felhom-samba entrypoint (R-7 slice 1). A dumb supervisor: smb.conf is bind-mounted # READ-ONLY by the controller, so nothing here templates config or bakes a secret. It # only ensures the household unix user exists (uid:gid 1000) and launches the three # discovery daemons. Verdict source: SPIKE-lan-discovery-2026-07-18 (S4/S4b). set -e FELHOM_UID="${FELHOM_UID:-1000}" FELHOM_GID="${FELHOM_GID:-1000}" SERVER_NAME="${FELHOM_SERVER_NAME:-FELHOM}" IFACE="${FELHOM_IFACE:-eth0}" # Household group/user at uid:gid 1000 — files written over SMB then match the app + # backup ownership convention (smb.conf sets `force user = felhom` per share). if ! getent group "$FELHOM_GID" >/dev/null 2>&1; then addgroup -g "$FELHOM_GID" felhom 2>/dev/null || true fi GRP_NAME="$(getent group "$FELHOM_GID" 2>/dev/null | cut -d: -f1)" [ -z "$GRP_NAME" ] && GRP_NAME=felhom if ! getent passwd "$FELHOM_UID" >/dev/null 2>&1; then adduser -D -H -u "$FELHOM_UID" -G "$GRP_NAME" -s /sbin/nologin felhom 2>/dev/null || true fi mkdir -p /var/lib/samba/private /run/samba # --- mDNS / Bonjour (v1.1.0) ------------------------------------------------------------- # THE macOS path. Templated from SERVER_NAME rather than baked, so renaming the server in the # UI re-advertises under the new name on the next container recreate — a baked name would # leave the box answering to something the customer no longer sees anywhere. # # A STATIC service file, deliberately, rather than smbd's own `multicast dns register`: it # needs no line in smb.conf (which is bind-mounted READ-ONLY and owned by the controller's # renderer) and it lets us publish _device-info._tcp so the Finder shows a sensible icon # instead of a generic globe. mkdir -p /etc/avahi/services /run/dbus cat > /etc/avahi/avahi-daemon.conf < /etc/avahi/services/smb.service < %h _smb._tcp 445 _device-info._tcp 0 model=RackMac CONF echo "[felhom-samba] launching nmbd + wsdd + avahi + smbd (server=${SERVER_NAME} iface=${IFACE} uid=${FELHOM_UID})" # nmbd: NetBIOS flat-name resolution so \\ resolves and mounts on WINDOWS (the S4b fix). # It does NOT serve macOS — see the Dockerfile header for the captured proof. nmbd --daemon --no-process-group # wsdd: WS-Discovery so the box appears in Windows Explorer's Network view. wsdd -i "$IFACE" -4 -H 4 -s -n "$SERVER_NAME" -w WORKGROUP & # dbus + avahi: mDNS, so `smb://.local` resolves and the box appears in the Finder sidebar. # Non-fatal on failure: sharing over an address still works, and refusing to start smbd because # a discovery daemon did not come up would turn a convenience gap into an outage. dbus-daemon --system --fork 2>/dev/null || echo "[felhom-samba] WARN: dbus failed to start — mDNS disabled" avahi-daemon --daemonize --no-drop-root 2>/dev/null || echo "[felhom-samba] WARN: avahi failed to start — mDNS disabled" # smbd in the foreground = the container's main process. exec smbd --foreground --no-process-group