diff options
| author | Guilhem Moulin <guilhem@fripost.org> | 2025-05-21 22:04:50 +0200 | 
|---|---|---|
| committer | Guilhem Moulin <guilhem@fripost.org> | 2025-05-21 22:06:22 +0200 | 
| commit | 2cd6bc6e4a1d73a14af0acb3b884f01da9524986 (patch) | |
| tree | 975ea1385a1f2c4491c2ae0670e01350fd7ba2a7 | |
| parent | 89888c3c1eae271b83e0ab6c5e53485370f46101 (diff) | |
webmap-download: Use --lockdir=%t/lock/webmap/cache
| -rw-r--r-- | files/etc/systemd/system/webmap-download@.service | 8 | ||||
| -rw-r--r-- | files/etc/tmpfiles.d/webmap.conf | 7 | 
2 files changed, 8 insertions, 7 deletions
| diff --git a/files/etc/systemd/system/webmap-download@.service b/files/etc/systemd/system/webmap-download@.service index e6b7f44..d7a49dc 100644 --- a/files/etc/systemd/system/webmap-download@.service +++ b/files/etc/systemd/system/webmap-download@.service @@ -15,8 +15,8 @@ IOSchedulingClass=idle  Type=oneshot  ExecStart=/usr/local/bin/webmap-download \ -    --cachedir=/var/cache/webmap \ -    --lockdir=%t/lock/webmap/download \ +    --cachedir=%C/webmap \ +    --lockdir=%t/lock/webmap/cache \      --no-exit-code \      --quiet \      -- %I @@ -30,8 +30,8 @@ ProtectControlGroups=yes  ProtectKernelModules=yes  ProtectKernelTunables=yes  RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 -ReadWritePaths=/var/cache/webmap -ReadWritePaths=%t/lock/webmap/download +ReadWritePaths=%C/webmap +ReadWritePaths=%t/lock/webmap/cache  [Install]  WantedBy=webmap-update@%i.target diff --git a/files/etc/tmpfiles.d/webmap.conf b/files/etc/tmpfiles.d/webmap.conf index 620cd24..b6fa8be 100644 --- a/files/etc/tmpfiles.d/webmap.conf +++ b/files/etc/tmpfiles.d/webmap.conf @@ -1,7 +1,8 @@ -d %t/lock/webmap            0755 root root +d %t/lock/webmap            00755 root root -# for webmap-download's --lockdir -d %t/lock/webmap/download   0755 _webmap-download _webmap +# for `webmap-download --lockdir` *and* `webmap-import --lockdir-sources` +# (hence the set-group-ID bit and g+w) +d %t/lock/webmap/cache      02775 _webmap-download _webmap  # for webmap-import's *and* webmap-publish's --lockfile (hence the  # ownership and g+w) | 
