diff --git a/.github/workflows/remote-support-v1.yml b/.github/workflows/remote-support-v1.yml index 8d1d5639..fc137c27 100644 --- a/.github/workflows/remote-support-v1.yml +++ b/.github/workflows/remote-support-v1.yml @@ -38,12 +38,16 @@ jobs: - name: Systemd activation links run: | set -Eeuo pipefail - test -f etc/systemd/system/pincabos-remote-support.service + unit='etc/systemd/system/pincabos-remote-support.service' + test -f "$unit" test -L etc/systemd/system/multi-user.target.wants/pincabos-remote-support.service test -L etc/systemd/system/pincabos-webapp.service.wants/pincabos-remote-support.service test "$(readlink etc/systemd/system/multi-user.target.wants/pincabos-remote-support.service)" = '../pincabos-remote-support.service' test "$(readlink etc/systemd/system/pincabos-webapp.service.wants/pincabos-remote-support.service)" = '../pincabos-remote-support.service' - grep -Fq 'ConditionPathExists=/var/lib/pincabos-link/device.json' etc/systemd/system/pincabos-remote-support.service + grep -Fq 'ConditionPathExists=/var/lib/pincabos-link/device.json' "$unit" + grep -Fq 'StateDirectory=pincabos-remote-support' "$unit" + grep -Fq 'StateDirectoryMode=0700' "$unit" + ! grep -Fq 'ReadWritePaths=/var/lib/pincabos-remote-support' "$unit" - name: Update V4 scope run: | @@ -66,7 +70,7 @@ jobs: for rel in paths: allowed = bool(mod.allowed(rel)) build = bool(mod.allowed_for_build(rel)) - print(('GO [OK]' if allowed and build else 'NOGO [!!]'), rel, 'allowed=', allowed, 'build=', build) + print(('GO [OK]' if allowed and build else 'NOGO [FAIL]'), rel, 'allowed=', allowed, 'build=', build) if not (allowed and build): failed.append(rel) if failed: diff --git a/etc/systemd/system/pincabos-remote-support.service b/etc/systemd/system/pincabos-remote-support.service index 02755970..43215893 100644 --- a/etc/systemd/system/pincabos-remote-support.service +++ b/etc/systemd/system/pincabos-remote-support.service @@ -16,7 +16,8 @@ NoNewPrivileges=false PrivateTmp=true ProtectSystem=full ProtectHome=false -ReadWritePaths=/var/lib/pincabos-remote-support /home/pinball/.ssh +StateDirectory=pincabos-remote-support +StateDirectoryMode=0700 [Install] WantedBy=multi-user.target