fix(mail): drop stale Amavis pid files on container restart

docker restart keeps /run, so Amavis's leftover pid can now belong to
Dovecot and Net::Server abort-loops instead of listening on 10026.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Francisco Trillo
2026-09-13 19:47:25 +02:00
co-authored by Cursor
parent 30ae48a4d6
commit b7d53e9750
2 changed files with 29 additions and 1 deletions
+25 -1
View File
@@ -25,7 +25,11 @@
# (no network), hand the mount to the `clamav` user, and create clamd's socket
# directory. Without a database clamd exits 1, and amavis — whose only scanner
# it is — then defers every inbound message (issue #565).
# 7. hand off to supervisord (the CMD).
# 8. Amavis: drop leftover pid/lock/socket. `docker recreate` empties /run;
# `docker restart` keeps the writable layer, so Net::Server can abort-loop
# against a recycled PID (often now dovecot) and Postfix defers originating
# mail on 127.0.0.1:10026.
# 9. hand off to supervisord (the CMD).
#
# Env (from ensure-container-mail.ts --env-file): FIRST_DOMAIN,
# OPENSHIP_MAIL_DB_{HOST,PORT,NAME,USER}, plus iRedMail secrets
@@ -212,5 +216,25 @@ else
log "WARN: no clamav user in this image — ClamAV will not start"
fi
# 8. Amavis runtime files.
#
# Amavis's Net::Server refuses to start if amavisd.pid exists and that PID is
# still alive — even when the process is something else. `/run` is empty on
# `docker recreate`, but `docker restart` keeps the writable layer, so a pid
# from the previous life can now belong to dovecot (PIDs recycle from 1).
# Supervisord then reports amavis STARTING/RUNNING while it abort-loops on
# "Pid_file already exists", and originating mail sits deferred with
# `connect to 127.0.0.1[127.0.0.1]:10026: Connection refused`.
#
# This entrypoint is the first process in a fresh pid namespace, so those
# files cannot refer to a living amavis. Drop them unconditionally, then
# recreate the directory the way Debian's tmpfiles.d rule would under
# systemd (supervisord has no equivalent).
if getent passwd amavis >/dev/null 2>&1; then
rm -f /var/run/amavis/amavisd.pid /var/run/amavis/amavisd.lock /var/run/amavis/amavisd.socket
install -d -m 0750 -o amavis -g amavis /var/run/amavis \
|| log "WARN: could not create /var/run/amavis — amavis cannot write its pid file"
fi
log "starting supervisord"
exec "$@"
+4
View File
@@ -57,6 +57,10 @@ stdout_logfile=/var/log/supervisor/%(program_name)s.log
[program:amavis]
# Debian's amavisd-new package installs the daemon as /usr/sbin/amavisd (there is
# no `amavisd-new` executable); `foreground` keeps it attached for supervisord.
# The entrypoint unlinks leftover /var/run/amavis/amavisd.{pid,lock,socket}
# before we start: Net::Server abort-loops if a docker-restart pid file still
# names a live non-amavis process (usually dovecot), and originating mail then
# defers on 127.0.0.1:10026.
command=/usr/sbin/amavisd foreground
autorestart=true
priority=30