From 39a27cb4272002014c8fbc908b87fd2a06f49fc2 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 21 Aug 2026 19:29:50 +0000 Subject: [PATCH] docuseal: use DocuSeal's patched PDFium build to fix service start DocuSeal switched to its own PDFium fork (upstream commit "adjust pdfium", 2026-08-15) and now attaches functions that only exist in that build, e.g. FPDFPage_GetAnnotCountRaw from the added fpdf_annots_raw.h. The generic bblanchon/pdfium-binaries library the script installed does not export them, so lib/pdfium.rb raises FFI::NotFoundError while Rails eager-loads and both docuseal.service and docuseal-sidekiq.service fail to start: Unable to load application: FFI::NotFoundError: Function 'FPDFPage_GetAnnotCountRaw' not found in [libpdfium.so] Install the library from docusealco/pdfium-binaries instead, matching the upstream Dockerfile. It is only published as a musl build (DocuSeal's image is Alpine based), so the musl runtime is installed and its library directory is added to the loader search path - the shared object needs "libc.so" (musl) at dlopen time. Verified on glibc: the library loads, resolves the raw annotation functions and renders pages correctly. The update path now refreshes PDFium too, so existing containers are repaired by running "update" even when DocuSeal itself is already up to date. --- ct/docuseal.sh | 14 ++++++++++++++ install/docuseal-install.sh | 24 +++++++++++++++--------- 2 files changed, 29 insertions(+), 9 deletions(-) diff --git a/ct/docuseal.sh b/ct/docuseal.sh index 9fbdca313..bd80ecf04 100644 --- a/ct/docuseal.sh +++ b/ct/docuseal.sh @@ -30,6 +30,20 @@ function update_script() { exit fi + # DocuSeal moved to its own patched PDFium build (FPDFPage_GetAnnotCountRaw & co.), + # which is only published as a musl binary, so existing installs need it swapped in. + ensure_dependencies musl + [[ -f /opt/pdfium/lib/libpdfium.so ]] || rm -f "$HOME/.pdfium" + fetch_and_deploy_gh_release "pdfium" "docusealco/pdfium-binaries" "prebuild" "latest" "/opt/pdfium" "pdfium-musl-$(uname -m).zip" + if ! cmp -s /opt/pdfium/lib/libpdfium.so /usr/lib/libpdfium.so; then + msg_info "Updating PDFium" + install -m 644 /opt/pdfium/lib/libpdfium.so /usr/lib/libpdfium.so + echo "/usr/lib/$(uname -m)-linux-musl" >/etc/ld.so.conf.d/musl.conf + $STD ldconfig + systemctl restart docuseal docuseal-sidekiq 2>/dev/null || true + msg_ok "Updated PDFium" + fi + if check_for_gh_release "docuseal" "docusealco/docuseal"; then msg_info "Stopping Services" systemctl stop docuseal docuseal-sidekiq diff --git a/install/docuseal-install.sh b/install/docuseal-install.sh index e502256e3..7e2fd9e5f 100644 --- a/install/docuseal-install.sh +++ b/install/docuseal-install.sh @@ -29,16 +29,16 @@ $STD apt install -y \ libvips-dev \ libheif1 \ redis-server \ - fontconfig + fontconfig \ + musl msg_ok "Installed Dependencies" NODE_VERSION="22" NODE_MODULE="yarn" setup_nodejs PG_VERSION="17" setup_postgresql PG_DB_NAME="docuseal" PG_DB_USER="docuseal" setup_postgresql_db -msg_info "Downloading Fonts and PDFium" +msg_info "Downloading Fonts" mkdir -p /opt/fonts /usr/share/fonts/noto -ARCH=$(uname -m | sed 's/x86_64/x64/;s/aarch64/arm64/') curl -fsSL -o /opt/fonts/GoNotoKurrent-Regular.ttf \ https://github.com/satbyy/go-noto-universal/releases/download/v7.0/GoNotoKurrent-Regular.ttf curl -fsSL -o /opt/fonts/GoNotoKurrent-Bold.ttf \ @@ -48,12 +48,18 @@ curl -fsSL -o /opt/fonts/DancingScript-Regular.otf \ ln -sf /opt/fonts/GoNotoKurrent-Regular.ttf /usr/share/fonts/noto/ ln -sf /opt/fonts/GoNotoKurrent-Bold.ttf /usr/share/fonts/noto/ $STD fc-cache -f -curl -fsSL -o /tmp/pdfium.tgz \ - "https://github.com/bblanchon/pdfium-binaries/releases/latest/download/pdfium-linux-${ARCH}.tgz" -mkdir -p /tmp/pdfium && tar -xzf /tmp/pdfium.tgz -C /tmp/pdfium -cp /tmp/pdfium/lib/libpdfium.so /usr/lib/libpdfium.so -rm -rf /tmp/pdfium /tmp/pdfium.tgz -msg_ok "Downloaded Fonts and PDFium" +msg_ok "Downloaded Fonts" + +# DocuSeal calls PDFium functions that only exist in its own patched build +# (FPDFPage_GetAnnotCountRaw & co.), so the upstream binaries are used. They are +# only published as musl builds, which need the musl runtime to be loadable. +fetch_and_deploy_gh_release "pdfium" "docusealco/pdfium-binaries" "prebuild" "latest" "/opt/pdfium" "pdfium-musl-$(uname -m).zip" + +msg_info "Installing PDFium" +install -m 644 /opt/pdfium/lib/libpdfium.so /usr/lib/libpdfium.so +echo "/usr/lib/$(uname -m)-linux-musl" >/etc/ld.so.conf.d/musl.conf +$STD ldconfig +msg_ok "Installed PDFium" fetch_and_deploy_gh_release "docuseal" "docusealco/docuseal" "tarball"