From: Thomas Lamprecht <t.lamprecht@proxmox.com>
To: Proxmox VE development discussion <pve-devel@lists.proxmox.com>,
Fiona Ebner <f.ebner@proxmox.com>
Subject: Re: [pve-devel] [PATCH manager 1/4] add tpmfiles.d config to create /run/pve directory
Date: Wed, 14 May 2025 20:08:03 +0200 [thread overview]
Message-ID: <e8801885-0dae-4e29-aea4-c7dc542be750@proxmox.com> (raw)
In-Reply-To: <20250513105652.67403-2-f.ebner@proxmox.com>
Am 13.05.25 um 12:56 schrieb Fiona Ebner:
> The pve-lxc-syscalld systemd service currently uses /run/pve as a
> runtime directory. This means, that when the service is restarted, the
> directory will be recreated. But the /run/pve directory is not just
> used as the runtime directory of this service, but also for other
> things, e.g. storage tunnel and mtunnel sockets, container stderr logs
> as well as pull metric cache and lock, which will be lost when the
> service is restarted.
>
> The plan is to give the service its own runtime directory that is only
> used for that purpose and nothing else. However, this means the
> /run/pve directory will not get created automatically anymore (e.g.
> pull metric relies on the existence already). Add this tmpfiles.d
> configuration to create it automatically again. Note that the
> permissions/owner are different now. As the runtime directory, it was
> created with 0755 root:root. This tmpfiles.conf configuration
> aligns the permissions/owner with the ones /run/pve-cluster has, i.e.
> 0750 root:www-data.
>
> Signed-off-by: Fiona Ebner <f.ebner@proxmox.com>
> ---
>
> We could also opt for 0750 root:root, not sure.
Would indeed better match the currently used /run/pve ownership.
>
> configs/Makefile | 1 +
> configs/pve-tmpfiles.conf | 2 ++
> 2 files changed, 3 insertions(+)
> create mode 100644 configs/pve-tmpfiles.conf
>
> diff --git a/configs/Makefile b/configs/Makefile
> index fa586e28..36f4f75a 100644
> --- a/configs/Makefile
> +++ b/configs/Makefile
> @@ -14,6 +14,7 @@ install: country.dat vzdump.conf pve-sources.list pve-initramfs.conf pve-blackli
> install -D -m 0644 pve-initramfs.conf $(DESTDIR)/etc/initramfs-tools/conf.d/pve-initramfs.conf
> install -D -m 0644 country.dat $(DESTDIR)/usr/share/$(PACKAGE)/country.dat
> install -D -m 0644 proxmox-ve-default.link $(DESTDIR)/usr/lib/systemd/network/99-default.link.d/proxmox-mac-address-policy.conf
> + install -D -m 0644 pve-tmpfiles.conf $(DESTDIR)/usr/lib/tmpfiles.d/pve-tmpfiles.conf
You can use dh_installtmpfiles [0] for this and just add the relevant config in
a "debian/package.tmpfiles" file. With debhelper compat level 13 that helper
will be run by default [1], and as level 13 is the recommended level for Trixie,
I plan to switch all packages over to that anyway.
0: https://manpages.debian.org/trixie/debhelper/dh_installtmpfiles.1.en.html
1: https://manpages.debian.org/testing/debhelper/debhelper-compat-upgrade-checklist.7.en.html#v13
>
> clean:
> rm -f country.dat
> diff --git a/configs/pve-tmpfiles.conf b/configs/pve-tmpfiles.conf
> new file mode 100644
> index 00000000..01c3275b
> --- /dev/null
> +++ b/configs/pve-tmpfiles.conf
> @@ -0,0 +1,2 @@
> +#Type Path Mode User Group Age Argument
> +d /run/pve 0750 root www-data - -
_______________________________________________
pve-devel mailing list
pve-devel@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel
next prev parent reply other threads:[~2025-05-14 18:08 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-05-13 10:56 [pve-devel] [RFC manager/lxc-syscalld/container 0/4] avoid using generic runtime directory name for pve-lxc-syscalld Fiona Ebner
2025-05-13 10:56 ` [pve-devel] [PATCH manager 1/4] add tpmfiles.d config to create /run/pve directory Fiona Ebner
2025-05-14 18:08 ` Thomas Lamprecht [this message]
2025-05-15 8:26 ` Fiona Ebner
2025-05-13 10:56 ` [pve-devel] [PATCH pve-lxc-syscalld 2/4] service: avoid using generic runtime directory name Fiona Ebner
2025-05-14 14:33 ` Thomas Lamprecht
2025-05-15 8:41 ` Fiona Ebner
2025-05-15 9:24 ` Thomas Lamprecht
2025-05-13 10:56 ` [pve-devel] [PATCH pve-lxc-syscalld 3/4] d/postinst: create link to new socket location on upgrade Fiona Ebner
2025-05-13 10:56 ` [pve-devel] [PATCH container 4/4] seccomp config: adapt to new lxc-syscalld runtime directory Fiona Ebner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e8801885-0dae-4e29-aea4-c7dc542be750@proxmox.com \
--to=t.lamprecht@proxmox.com \
--cc=f.ebner@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal