all lists on lists.proxmox.com
 help / color / mirror / Atom feed
* [pve-devel] [PATCH manager] d/tmpfiles: fix permission regression for /run/pve directory
@ 2025-08-05 10:03 Fiona Ebner
  2025-08-05 10:10 ` Hannes Laimer
                   ` (3 more replies)
  0 siblings, 4 replies; 6+ messages in thread
From: Fiona Ebner @ 2025-08-05 10:03 UTC (permalink / raw)
  To: pve-devel

There is a regression regarding the permission for the /run/pve
directory. In Proxmox VE 8, the directory had root:root 0755
permissions, being auto-created as the lxc-syscalld runtime directory.
In Proxmox VE 9, the permissions were restricted to root:root 0750,
but this leads to an issue with remote migration, when pveproxy tries
to access the mtunnel socket:

pveproxy[2484]: connect to 'unix/:/run/pve/ct-112.mtunnel' failed: Permission denied

Relax the permissions again by allowing the www-data group
read-access, so that pveproxy can access the socket.

This aligns the permissions with what /run/pve-cluster has.

Reported-by: Hannes Laimer <h.laimer@proxmox.com>
Signed-off-by: Fiona Ebner <f.ebner@proxmox.com>
---
 debian/tmpfiles | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/debian/tmpfiles b/debian/tmpfiles
index 98b8fb96..1263300f 100644
--- a/debian/tmpfiles
+++ b/debian/tmpfiles
@@ -1,2 +1,2 @@
-#Type Path     Mode User Group Age Argument
-d     /run/pve 0750 root root  -   -
+#Type Path     Mode User Group     Age Argument
+d     /run/pve 0750 root www-data  -   -
-- 
2.47.2



_______________________________________________
pve-devel mailing list
pve-devel@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2025-08-05 13:10 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-08-05 10:03 [pve-devel] [PATCH manager] d/tmpfiles: fix permission regression for /run/pve directory Fiona Ebner
2025-08-05 10:10 ` Hannes Laimer
2025-08-05 10:20 ` Fabian Grünbichler
2025-08-05 10:36   ` Thomas Lamprecht
2025-08-05 10:24 ` [pve-devel] applied: " Thomas Lamprecht
2025-08-05 13:11 ` Thomas Lamprecht

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal