- rootfs/usr/local/bin/entrypoint.sh: the "start all services" gate
(`if [ "$START_SERVICES" = "yes" ] || [ -z "$1" ]`) always evaluated true
on a first-run container regardless of $1, because START_SERVICES is
force-set to "yes" whenever no PID file exists yet. This meant any
command passed to `docker run` — `exec ...`, `sh -c ...`, `shell`, or an
arbitrary program — was swallowed into the service-start+monitor branch
before ever reaching the `case "$1"` statement that already handles
those subcommands correctly, causing the container to hang as a
persistent daemon instead of running the given command. Changed the
condition to `if [ -z "$1" ]` so the daemon branch only fires when no
command was given at all, matching the default case's own `$# -eq 0`
check further down. Verified `bash -n` passes; script-lint confirms the
edited block is clean (3 unrelated pre-existing findings logged to
TODO.AI.md).
- TODO.AI.md: logged 3 pre-existing script-lint findings in this same
file (two bare `exit` statements, one missing VERSION= stamp) found
incidentally while linting the fix above — out of scope for this
change since this file is regenerated wholesale from the shared
upstream template.