From: Fiona Ebner <f.ebner@proxmox.com>
To: Thomas Lamprecht <t.lamprecht@proxmox.com>,
Proxmox VE development discussion <pve-devel@lists.proxmox.com>
Subject: Re: [pve-devel] [PATCH pve-lxc-syscalld 2/4] service: avoid using generic runtime directory name
Date: Thu, 15 May 2025 10:41:49 +0200 [thread overview]
Message-ID: <dca67e16-8e56-4281-9526-1d5c9e843b90@proxmox.com> (raw)
In-Reply-To: <885a462e-aa47-46c6-97dd-647b1c7dc9ed@proxmox.com>
Am 14.05.25 um 16:33 schrieb Thomas Lamprecht:
> Am 13.05.25 um 12:56 schrieb Fiona Ebner:
>> When the service is restarted, the directory will be recreated. The
>> issue is that the /run/pve directory is not just used as the runtime
>> directory of this service, but also for other things, e.g. storage
>> tunnel and mtunnel sockets and container stderr logs as well as pull
>> metrics, which will be lost when the service is restarted.
>
> Is there much gained by moving the socket path or would it be enough to
> drop the RundtimeDirectory completely or do we want to rely on the
> clean-up being done by systemd? Which probably is an OK enough reason,
> I'd think..
Yes, the cleanup aspect is there and it seems nicer to have a dedicated
directory IMHO. It would avoid the need to adapt pve-container and the
postinst snippet, but I'd still like to go for the "dedicated
RuntimeDirectory" approach.
> btw., to name all options, there would be the RuntimeDirectoryPreserve=
> property for systemd services (documented in man systemd.exec) which
> we could set to `restart` to handle just updates or `yes` to never clean
> it up; besides obviously a system reboot clearing any tmpfs, that is.
That option would not help with the awkward dependency/reliance on the
service to create the /run/pve directory in the first place. And even if
it's created by the tmpfiles.d snippet in pve-manager first, it will get
overwritten (with root:root 0755 permissions) when its first used as the
service's runtime directory.
>>
>> Signed-off-by: Fiona Ebner <f.ebner@proxmox.com>
>> ---
>>
>> Versioned breaks for pve-container and pve-manager needed.
>>
>> etc/pve-lxc-syscalld.service.in | 4 ++--
>> 1 file changed, 2 insertions(+), 2 deletions(-)
>>
>> diff --git a/etc/pve-lxc-syscalld.service.in b/etc/pve-lxc-syscalld.service.in
>> index be076a7..0557fe6 100644
>> --- a/etc/pve-lxc-syscalld.service.in
>> +++ b/etc/pve-lxc-syscalld.service.in
>> @@ -4,8 +4,8 @@ Before=pve-guests.service
>>
>> [Service]
>> Type=notify
>> -ExecStart=%LIBEXECDIR%/pve-lxc-syscalld/pve-lxc-syscalld --system /run/pve/lxc-syscalld.sock
>> -RuntimeDirectory=pve
>> +ExecStart=%LIBEXECDIR%/pve-lxc-syscalld/pve-lxc-syscalld --system /run/pve-lxc-syscalld/lxc-syscalld.sock
>
> If we go for a dedicated directory we could drop the redundancy in the
> file name, e.g.
>
> /run/pve-lxc-syscalld/sock
>
> or
>
> /run/pve-lxc-syscalld/socket
Okay, I'll go for the latter in v2.
_______________________________________________
pve-devel mailing list
pve-devel@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel
next prev parent reply other threads:[~2025-05-15 8:41 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-05-13 10:56 [pve-devel] [RFC manager/lxc-syscalld/container 0/4] avoid using generic runtime directory name for pve-lxc-syscalld Fiona Ebner
2025-05-13 10:56 ` [pve-devel] [PATCH manager 1/4] add tpmfiles.d config to create /run/pve directory Fiona Ebner
2025-05-14 18:08 ` Thomas Lamprecht
2025-05-15 8:26 ` Fiona Ebner
2025-05-13 10:56 ` [pve-devel] [PATCH pve-lxc-syscalld 2/4] service: avoid using generic runtime directory name Fiona Ebner
2025-05-14 14:33 ` Thomas Lamprecht
2025-05-15 8:41 ` Fiona Ebner [this message]
2025-05-15 9:24 ` Thomas Lamprecht
2025-05-13 10:56 ` [pve-devel] [PATCH pve-lxc-syscalld 3/4] d/postinst: create link to new socket location on upgrade Fiona Ebner
2025-05-13 10:56 ` [pve-devel] [PATCH container 4/4] seccomp config: adapt to new lxc-syscalld runtime directory Fiona Ebner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=dca67e16-8e56-4281-9526-1d5c9e843b90@proxmox.com \
--to=f.ebner@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
--cc=t.lamprecht@proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal