From: Christian Ebner <c.ebner@proxmox.com>
To: Robert Obkircher <r.obkircher@proxmox.com>, pbs-devel@lists.proxmox.com
Subject: Re: [PATCH proxmox-backup v3 04/15] pbs-config: use proxmox-product-config::replace_config()
Date: Mon, 20 Jul 2026 16:13:23 +0200 [thread overview]
Message-ID: <73210cac-6083-4eb5-80f1-49b1770f15cf@proxmox.com> (raw)
In-Reply-To: <0a702b2c-de13-433a-ae33-1ca51e172e82@proxmox.com>
On 7/6/26 2:28 PM, Robert Obkircher wrote:
>
> On 01.07.26 16:05, Christian Ebner wrote:
>> Instead of using the pbs-config local implementation, use the product
>> general implementation, dropping the local one instead.
>>
>> Since proxmox-product-config::replace_config() requires the api- and
>> priv-user to be initialized a-priori, any calling codepath must
>> guarantee to have run proxmox-product-config::init() once.
>>
>> [..]
>>
>> -/// Atomically write data to file owned by "root:backup" with permission "0640"
>> -///
>> -/// Only the superuser can write those files, but group 'backup' can read them.
>> -pub fn replace_backup_config<P: AsRef<std::path::Path>>(path: P, data: &[u8]) -> Result<(), Error> {
>> - let backup_user = backup_user()?;
>> - let mode = nix::sys::stat::Mode::from_bits_truncate(0o0640);
>> - // set the correct owner/group/permissions while saving file
>> - // owner(rw) = root, group(r)= backup
>> - let options = proxmox_sys::fs::CreateOptions::new()
>> - .perm(mode)
>> - .owner(nix::unistd::ROOT)
>> - .group(backup_user.gid);
>> -
>> - proxmox_sys::fs::replace_file(path, data, options, true)?;
>> -
>> - Ok(())
>> -}
>>
>> [..]
>>
>> pub fn save_config(config: &SectionConfigData) -> Result<(), Error> {
>> let raw = CONFIG.write(METRIC_SERVER_CFG_FILENAME, config)?;
>> - crate::replace_backup_config(METRIC_SERVER_CFG_FILENAME, raw.as_bytes())
>> + replace_config(METRIC_SERVER_CFG_FILENAME, raw.as_bytes())
>> }
>>
>> [..]
> This changes the permissions from root:backup to backup:backup!
>
> I think the correct function would be
> proxmox_product_config::replace_privileged_config.
>
> (Applies to all changes in this patch)
Good catch! Will be fixed in v4!
next prev parent reply other threads:[~2026-07-20 14:13 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-01 14:03 [PATCH proxmox-backup v3 00/15] fix 7642: avoid expensive uid/gid lookups for lock- and config-files Christian Ebner
2026-07-01 14:03 ` [PATCH proxmox-backup v3 01/15] bin: api: early init proxmox-product-config Christian Ebner
2026-07-06 10:06 ` Robert Obkircher
2026-07-01 14:03 ` [PATCH proxmox-backup v3 02/15] bin: daily update: refactor to use proxmox-product-config Christian Ebner
2026-07-01 14:04 ` [PATCH proxmox-backup v3 03/15] pbs-config: use proxmox-product-config::replace_secret_config() Christian Ebner
2026-07-06 12:28 ` Robert Obkircher
2026-07-01 14:04 ` [PATCH proxmox-backup v3 04/15] pbs-config: use proxmox-product-config::replace_config() Christian Ebner
2026-07-06 12:28 ` Robert Obkircher
2026-07-20 14:13 ` Christian Ebner [this message]
2026-07-01 14:04 ` [PATCH proxmox-backup v3 05/15] fix #7642: avoid expensive user lookups on file locking Christian Ebner
2026-07-01 14:04 ` [PATCH proxmox-backup v3 06/15] pbs-config: use proxmox-product-config helpers Christian Ebner
2026-07-01 14:04 ` [PATCH proxmox-backup v3 07/15] pbs-config: drop backup_group helper, use users gid instead Christian Ebner
2026-07-06 12:28 ` Robert Obkircher
2026-07-01 14:04 ` [PATCH proxmox-backup v3 08/15] pbs-datastore: use proxmox-product-config cached backup user Christian Ebner
2026-07-01 14:04 ` [PATCH proxmox-backup v3 09/15] pbs-datastore: use general helpers for file lock create options Christian Ebner
2026-07-01 14:04 ` [PATCH proxmox-backup v3 10/15] server: auth helpers: use proxmox-product-config create options helpers Christian Ebner
2026-07-01 14:04 ` [PATCH proxmox-backup v3 11/15] api: subscription: use proxmox-product-config create options Christian Ebner
2026-07-01 14:04 ` [PATCH proxmox-backup v3 12/15] tape: use proxmox-product-config helper for user lookup Christian Ebner
2026-07-06 12:28 ` Robert Obkircher
2026-07-01 14:04 ` [PATCH proxmox-backup v3 13/15] tape: use proxmox-product-config lock file create options Christian Ebner
2026-07-01 14:04 ` [PATCH proxmox-backup v3 14/15] tape: use proxmox-product-config to generate " Christian Ebner
2026-07-06 12:29 ` Robert Obkircher
2026-07-20 14:12 ` Christian Ebner
2026-07-20 15:19 ` Robert Obkircher
2026-07-21 8:26 ` Christian Ebner
2026-07-21 8:58 ` Robert Obkircher
2026-07-01 14:04 ` [PATCH proxmox-backup v3 15/15] tree-wide: use proxmox-product-config::get_api_user for user lookup Christian Ebner
2026-07-20 14:17 ` superseded: [PATCH proxmox-backup v3 00/15] fix 7642: avoid expensive uid/gid lookups for lock- and config-files Christian Ebner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=73210cac-6083-4eb5-80f1-49b1770f15cf@proxmox.com \
--to=c.ebner@proxmox.com \
--cc=pbs-devel@lists.proxmox.com \
--cc=r.obkircher@proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox