Fix onnxruntime executable stack error in Docker build

The onnxruntime library requires an executable stack which is blocked
by security restrictions in Docker containers. This adds execstack tool
and uses it to clear the executable stack flag after pip install.

https://claude.ai/code/session_01AGoPJaXqdJnnuxtmSv6NLR
This commit is contained in:
Claude
2026-01-27 04:49:32 +00:00
parent dd4cd99e79
commit a1dd81b981
+6
View File
@@ -22,6 +22,7 @@ FROM python:3.11-slim
WORKDIR /app
# Install system dependencies for OpenCV, rembg, SAM, and image processing
# execstack is needed to fix onnxruntime executable stack issue in containers
RUN apt-get update && apt-get install -y \
libgl1 \
libglib2.0-0 \
@@ -31,12 +32,17 @@ RUN apt-get update && apt-get install -y \
libgomp1 \
wget \
git \
execstack \
&& rm -rf /var/lib/apt/lists/*
# Copy requirements and install Python dependencies
COPY backend/requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
# Fix onnxruntime executable stack issue in containers
# This clears the executable stack requirement from the onnxruntime library
RUN execstack -c /usr/local/lib/python3.11/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-311-x86_64-linux-gnu.so || true
# Pre-download rembg model (u2net) to avoid first-run delay
# Note: This downloads the U2-Net model (~170MB) during build
RUN python -c "from rembg import remove; print('rembg model downloaded')"