Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Let systemd create directories #3122

Open
wants to merge 1 commit into
base: develop
Choose a base branch
from

Conversation

gchamp20
Copy link

@gchamp20 gchamp20 commented Oct 4, 2024

Context

Manually creating directories conflicts with systemd service hardening features. Particularly, ProtectSystem=strict mounts the filesystem has read-only for the processes started by the unit which leads to mkdir failing.

By setting User=mosquitto and adding RuntimeDirectory and LogsDirectory, systemd creates /run/mosquitto and /var/log/mosquitto with the right permissions even ProtectSystem=strict is used.

Adding User=mosquitto also has the side effect of running the daemon as the user mosquitto. I

Checklist

  • Have you signed the Eclipse Contributor Agreement, using the same email address as you used in your commits?
    https://accounts.eclipse.org/users/gchamp20, submitted, appears to be pending? I can still re-submit but I now get an error.

  • Do each of your commits have a "Signed-off-by" line, with the correct email address? Use "git commit -s" to generate this line for you.

  • If you are contributing a new feature, is your work based off the develop branch?

  • If you are contributing a bugfix, is your work based off the fixes branch?

  • Have you added an explanation of what your changes do and why you'd like us to include them?

  • Have you successfully run make test with your changes locally?

Manually creating directories conflicts with systemd service hardening
features. Particularly, `ProtectSystem=strict` mounts the filesystem as
read-only for the processes started by the unit which leads to `mkdir`
failing.

By setting `User=mosquitto` and adding `RuntimeDirectory` and
`LogsDirectory`, systemd creates `/run/mosquitto` and
`/var/log/mosquitto` with the right permissions even
`ProtectSystem=strict` is used.

Signed-off-by: Guillaume Champagne <[email protected]>
@gchamp20 gchamp20 force-pushed the enhance-systemd-service-example branch from 5fe6d40 to cb4d276 Compare October 4, 2024 21:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant