all lists on lists.proxmox.com
 help / color / mirror / Atom feed
From: Maximiliano Sandoval <m.sandoval@proxmox.com>
To: pmg-devel@lists.proxmox.com
Subject: [pmg-devel] [PATCH pmg-api v3 10/10] fix #4926: run pmg-smtp-filter and pmgpolicy without root rights
Date: Mon, 17 Jun 2024 16:18:07 +0200	[thread overview]
Message-ID: <20240617141807.722744-10-m.sandoval@proxmox.com> (raw)
In-Reply-To: <20240617141807.722744-1-m.sandoval@proxmox.com>

New users 'pmg-smpt-filter' and 'pmgpolicy' are created for their
respective processes and we set their systemd units to use them.

Signed-off-by: Maximiliano Sandoval <m.sandoval@proxmox.com>
---
 debian/pmg-smtp-filter.service | 2 ++
 debian/pmgpolicy.service       | 2 ++
 2 files changed, 4 insertions(+)

diff --git a/debian/pmg-smtp-filter.service b/debian/pmg-smtp-filter.service
index c887dc2..c4d5e38 100644
--- a/debian/pmg-smtp-filter.service
+++ b/debian/pmg-smtp-filter.service
@@ -16,6 +16,8 @@ Type=forking
 Restart=on-abort
 RestartSec=10
 RuntimeDirectory=pmg-smtp-filter
+User=pmg-smtp-filter
+Group=pmg-smtp-filter
 
 [Install]
 WantedBy=multi-user.target
diff --git a/debian/pmgpolicy.service b/debian/pmgpolicy.service
index 21a403f..cd8ee60 100644
--- a/debian/pmgpolicy.service
+++ b/debian/pmgpolicy.service
@@ -13,6 +13,8 @@ ExecReload=/bin/kill -HUP $MAINPID
 PIDFile=/run/pmgpolicy/pmgpolicy.pid
 Type=forking
 RuntimeDirectory=pmgpolicy
+User=pmgpolicy
+Group=pmgpolicy
 
 [Install]
 WantedBy=multi-user.target
-- 
2.39.2



_______________________________________________
pmg-devel mailing list
pmg-devel@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pmg-devel


      parent reply	other threads:[~2024-06-17 14:18 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-06-17 14:17 [pmg-devel] [PATCH pmg-api v3 01/10] pmgpolicy: move pid file into /run/pmgpolicy Maximiliano Sandoval
2024-06-17 14:17 ` [pmg-devel] [PATCH pmg-api v3 02/10] pmg-smtp-filter: move pid file into /run/pmg-smtp-filter Maximiliano Sandoval
2024-06-17 14:18 ` [pmg-devel] [PATCH pmg-api v3 03/10] config: store config lock in smtp-filter runtime dir Maximiliano Sandoval
2024-06-17 14:18 ` [pmg-devel] [PATCH pmg-api v3 04/10] create new users for the rule db Maximiliano Sandoval
2024-06-17 14:18 ` [pmg-devel] [PATCH pmg-api v3 05/10] postinstall: add new group for shared functionality Maximiliano Sandoval
2024-06-17 14:18 ` [pmg-devel] [PATCH pmg-api v3 06/10] postinstall: make rrdcached be readable by the pmg group Maximiliano Sandoval
2024-06-17 14:18 ` [pmg-devel] [PATCH pmg-api v3 07/10] spamasassin: store files in dir managed by pmg Maximiliano Sandoval
2024-06-17 14:18 ` [pmg-devel] [PATCH pmg-api v3 08/10] mailqueue: make mail queue writable by pmg group Maximiliano Sandoval
2024-06-17 14:18 ` [pmg-devel] [PATCH pmg-api v3 09/10] d/sysusers: add users for pmgpolicy and smtp-filter Maximiliano Sandoval
2024-06-17 14:18 ` Maximiliano Sandoval [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240617141807.722744-10-m.sandoval@proxmox.com \
    --to=m.sandoval@proxmox.com \
    --cc=pmg-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal