summaryrefslogtreecommitdiffstats
path: root/packaging
diff options
context:
space:
mode:
Diffstat (limited to 'packaging')
-rw-r--r--packaging/rpm/meshbay-node.spec11
-rw-r--r--packaging/systemd/meshbay-node-user.service63
2 files changed, 73 insertions, 1 deletions
diff --git a/packaging/rpm/meshbay-node.spec b/packaging/rpm/meshbay-node.spec
index 7052cff..5f28c52 100644
--- a/packaging/rpm/meshbay-node.spec
+++ b/packaging/rpm/meshbay-node.spec
@@ -40,8 +40,16 @@ Includes a local web UI at http://localhost:18000.
%install
%{python3} -m pip install --root %{buildroot} --no-index --find-links dist meshbay-node
-# systemd user service (template)
+# Two units, because there are two personas and one file cannot be both.
+#
+# The SYSTEM template carries User=%%i and is instantiated per person by root
+# (`systemctl enable --now meshbay-node@alice`) — the server case. A *user* unit
+# cannot carry User= at all: it already runs as its owner, and systemd refuses
+# the file. This spec used to install the template into the user unit directory,
+# where it could never have started.
install -Dm644 packaging/systemd/meshbay-node.service \
+ %{buildroot}%{_unitdir}/meshbay-node@.service
+install -Dm644 packaging/systemd/meshbay-node-user.service \
%{buildroot}%{_userunitdir}/meshbay-node.service
%files
@@ -50,6 +58,7 @@ install -Dm644 packaging/systemd/meshbay-node.service \
%{python3_sitelib}/meshbay_node/
%{python3_sitelib}/meshbay_node-*.dist-info/
%{_bindir}/meshbay-node
+%{_unitdir}/meshbay-node@.service
%{_userunitdir}/meshbay-node.service
%changelog
diff --git a/packaging/systemd/meshbay-node-user.service b/packaging/systemd/meshbay-node-user.service
new file mode 100644
index 0000000..833f31a
--- /dev/null
+++ b/packaging/systemd/meshbay-node-user.service
@@ -0,0 +1,63 @@
+[Unit]
+Description=MeshBay Node — P2P file host, streaming, and chat
+Documentation=https://meshbay.org/docs
+After=network-online.target
+Wants=network-online.target
+
+# The per-user unit, for the desktop persona.
+#
+# Its sibling `meshbay-node.service` is a SYSTEM template with `User=%i`, which
+# root instantiates once per person (`systemctl enable --now meshbay-node@alice`)
+# — the ordinary gesture on a server. That is the wrong shape for someone
+# running a node on their own machine: it needs a password they should not have
+# to give, for a service that only ever runs as them.
+#
+# This one is enabled by the person themselves, and therefore by the desktop
+# client on their behalf:
+#
+# systemctl --user enable --now meshbay-node
+# loginctl enable-linger $USER # keep serving when logged out
+#
+# A user unit cannot carry User= or Group= — it already runs as its owner.
+
+[Service]
+Type=simple
+
+# Secrets: MESHBAY_UNLOCK_KEY (keystore). MESHBAY_PASSWORD is no longer read —
+# the node authenticates to the hub with an Ed25519 signature (NS7).
+EnvironmentFile=-%h/.config/meshbay/node.env
+
+ExecStart=/usr/bin/meshbay-node --config %h/.config/meshbay/node.toml
+# The client asks for a reload after changing a group's directories, and that
+# must not drop a member who is watching a film.
+ExecReload=/bin/kill -HUP $MAINPID
+Restart=on-failure
+RestartSec=10
+TimeoutStopSec=30
+
+# Data: chat DBs, roster, indexes — ~/.local/share/meshbay/
+StateDirectory=meshbay
+
+# Security hardening
+NoNewPrivileges=true
+PrivateTmp=true
+ProtectSystem=strict
+ProtectHome=false
+ReadWritePaths=%h/.config/meshbay %h/.local/share/meshbay
+
+# A directory shared from outside the home — an external drive, another
+# partition — is added by a drop-in the client writes, rather than by weakening
+# ProtectSystem:
+#
+# ~/.config/systemd/user/meshbay-node.service.d/paths.conf
+# [Service]
+# ReadWritePaths=/run/media/%u/Films
+# RequiresMountsFor=/run/media/%u/Films
+#
+# RequiresMountsFor matters as much as the path: a unit with ProtectSystem gets
+# its own mount namespace, so a volume mounted on the host *after* this service
+# started is invisible inside it — the directory reads as empty even when
+# everything else is right.
+
+[Install]
+WantedBy=default.target