diff options
Diffstat (limited to 'packaging')
| -rw-r--r-- | packaging/rpm/meshbay-node.spec | 11 | ||||
| -rw-r--r-- | packaging/systemd/meshbay-node-user.service | 63 |
2 files changed, 73 insertions, 1 deletions
diff --git a/packaging/rpm/meshbay-node.spec b/packaging/rpm/meshbay-node.spec index 7052cff..5f28c52 100644 --- a/packaging/rpm/meshbay-node.spec +++ b/packaging/rpm/meshbay-node.spec @@ -40,8 +40,16 @@ Includes a local web UI at http://localhost:18000. %install %{python3} -m pip install --root %{buildroot} --no-index --find-links dist meshbay-node -# systemd user service (template) +# Two units, because there are two personas and one file cannot be both. +# +# The SYSTEM template carries User=%%i and is instantiated per person by root +# (`systemctl enable --now meshbay-node@alice`) — the server case. A *user* unit +# cannot carry User= at all: it already runs as its owner, and systemd refuses +# the file. This spec used to install the template into the user unit directory, +# where it could never have started. install -Dm644 packaging/systemd/meshbay-node.service \ + %{buildroot}%{_unitdir}/meshbay-node@.service +install -Dm644 packaging/systemd/meshbay-node-user.service \ %{buildroot}%{_userunitdir}/meshbay-node.service %files @@ -50,6 +58,7 @@ install -Dm644 packaging/systemd/meshbay-node.service \ %{python3_sitelib}/meshbay_node/ %{python3_sitelib}/meshbay_node-*.dist-info/ %{_bindir}/meshbay-node +%{_unitdir}/meshbay-node@.service %{_userunitdir}/meshbay-node.service %changelog diff --git a/packaging/systemd/meshbay-node-user.service b/packaging/systemd/meshbay-node-user.service new file mode 100644 index 0000000..833f31a --- /dev/null +++ b/packaging/systemd/meshbay-node-user.service @@ -0,0 +1,63 @@ +[Unit] +Description=MeshBay Node — P2P file host, streaming, and chat +Documentation=https://meshbay.org/docs +After=network-online.target +Wants=network-online.target + +# The per-user unit, for the desktop persona. +# +# Its sibling `meshbay-node.service` is a SYSTEM template with `User=%i`, which +# root instantiates once per person (`systemctl enable --now meshbay-node@alice`) +# — the ordinary gesture on a server. That is the wrong shape for someone +# running a node on their own machine: it needs a password they should not have +# to give, for a service that only ever runs as them. +# +# This one is enabled by the person themselves, and therefore by the desktop +# client on their behalf: +# +# systemctl --user enable --now meshbay-node +# loginctl enable-linger $USER # keep serving when logged out +# +# A user unit cannot carry User= or Group= — it already runs as its owner. + +[Service] +Type=simple + +# Secrets: MESHBAY_UNLOCK_KEY (keystore). MESHBAY_PASSWORD is no longer read — +# the node authenticates to the hub with an Ed25519 signature (NS7). +EnvironmentFile=-%h/.config/meshbay/node.env + +ExecStart=/usr/bin/meshbay-node --config %h/.config/meshbay/node.toml +# The client asks for a reload after changing a group's directories, and that +# must not drop a member who is watching a film. +ExecReload=/bin/kill -HUP $MAINPID +Restart=on-failure +RestartSec=10 +TimeoutStopSec=30 + +# Data: chat DBs, roster, indexes — ~/.local/share/meshbay/ +StateDirectory=meshbay + +# Security hardening +NoNewPrivileges=true +PrivateTmp=true +ProtectSystem=strict +ProtectHome=false +ReadWritePaths=%h/.config/meshbay %h/.local/share/meshbay + +# A directory shared from outside the home — an external drive, another +# partition — is added by a drop-in the client writes, rather than by weakening +# ProtectSystem: +# +# ~/.config/systemd/user/meshbay-node.service.d/paths.conf +# [Service] +# ReadWritePaths=/run/media/%u/Films +# RequiresMountsFor=/run/media/%u/Films +# +# RequiresMountsFor matters as much as the path: a unit with ProtectSystem gets +# its own mount namespace, so a volume mounted on the host *after* this service +# started is invisible inside it — the directory reads as empty even when +# everything else is right. + +[Install] +WantedBy=default.target |