From ccafd32cccc1d10645f1eec0f5d6117d8b00df2a Mon Sep 17 00:00:00 2001 From: Matt Hill <9935159+MattDHill@users.noreply.github.com> Date: Sun, 20 Sep 2026 12:03:42 -0600 Subject: [PATCH] =?UTF-8?q?fix:=20disable=20PHP's=20OPcache=20JIT;=2033.0.?= =?UTF-8?q?8=20=E2=86=92=2033.0.8.1?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The upstream image turns the tracing JIT on for every architecture (opcache.jit=1255, 8M buffer). On aarch64 it segfaults every php-fpm worker once an app install or update replaces files it has already compiled, and the workers keep dying on respawn, so every request 502s until the service is restarted and OPcache is flushed. Reported against this package on StartOS 0.3.5~1 and reproduced upstream (nextcloud/docker#2576, linuxserver/docker-nextcloud#514); the image maintainers consider it a PHP bug and won't change the default. A startos-opcache-jit.ini in conf.d sets opcache.jit=0 and opcache.jit_buffer_size=0. conf.d loads alphabetically, so it lands after opcache-recommended.ini; verified in nextcloud:33.0.8-fpm with the file mounted, php -i reports both as 0. Disabled on every architecture rather than gated on aarch64: Nextcloud gains little from the JIT, and the same tracing JIT has open segfault reports on x86-64 (php/php-src#22084, #22558). Co-Authored-By: Claude Opus 5 (1M context) --- Dockerfile | 5 +++++ manifest.yaml | 3 ++- scripts/services/migrations.ts | 16 +++++++++++++++- 3 files changed, 22 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 5e53932..e9ea112 100644 --- a/Dockerfile +++ b/Dockerfile @@ -23,6 +23,11 @@ RUN apt update && apt install -y --no-install-recommends \ && chmod a+rx /usr/local/bin/yt-dlp && \ apt clean && rm -rf /var/lib/apt/lists/* +# PHP's JIT segfaults every worker on aarch64 once an app update replaces +# compiled files. See https://github.com/nextcloud/docker/issues/2576 +RUN printf 'opcache.jit=0\nopcache.jit_buffer_size=0\n' \ + > "$PHP_INI_DIR/conf.d/startos-opcache-jit.ini" + # # Set environment variables ENV POSTGRES_DB=nextcloud ENV POSTGRES_USER=nextcloud diff --git a/manifest.yaml b/manifest.yaml index 398c971..e0ba1a7 100644 --- a/manifest.yaml +++ b/manifest.yaml @@ -1,7 +1,8 @@ id: nextcloud title: Nextcloud -version: 33.0.8 +version: 33.0.8.1 release-notes: | + * Fixes a crash after installing or updating an app on aarch64 servers that left Nextcloud unreachable until it was restarted. * Update to v33.0.8 - See [full changelog](https://nextcloud.com/changelog/) * After updating, start Nextcloud and wait for all health checks to pass. The database upgrade only completes while the service is running, so let it finish before updating StartOS to 0.4.0. license: AGPL-3.0 diff --git a/scripts/services/migrations.ts b/scripts/services/migrations.ts index 14d921e..bcd2971 100644 --- a/scripts/services/migrations.ts +++ b/scripts/services/migrations.ts @@ -1,7 +1,7 @@ import { EmVer } from "https://deno.land/x/embassyd_sdk@v0.3.3.0.9/emver-lite/mod.ts"; import { compat, matches, util, types as T } from "../deps.ts"; -const current = "33.0.8"; +const current = "33.0.8.1"; const currentMajor = EmVer.parse(current).values[0]; const minMajor = currentMajor - 1; @@ -233,6 +233,20 @@ export const migration: T.ExpectedExports.migration = async ( ); }, }, + "33.0.8.1": { + up: compat.migrations.updateConfig( + (config) => { + return config; + }, + true, + { version: "33.0.8.1", type: "up" } + ), + down: () => { + throw new Error( + "Downgrades are prohibited per Nextcloud development team recommendations" + ); + }, + }, }, current )(effects, version, ...args);