fix(nix): explicitly create parent directories for dataDir in tmpfiles

The tmpfiles.rules now explicitly creates the parent directory of dataDir
with root:root ownership and 0755 permissions before creating the
service-owned directories. This ensures the directory hierarchy exists
even if parent directories are missing.

While systemd-tmpfiles should create parent directories automatically,
this makes the behavior explicit and ensures proper permissions on the
immediate parent directory.
This commit is contained in:
DanConwayDev
2026-01-21 15:13:45 +00:00
parent 6c3c93752e
commit 81ef29e858
+5
View File
@@ -459,7 +459,12 @@ in {
# Create data directories with proper ownership using tmpfiles
# This runs as root before the service starts
# Note: Parent directories are created with root:root ownership (mode 0755)
# to ensure the path exists, while dataDir itself gets proper service ownership
systemd.tmpfiles.rules = flatten (mapAttrsToList (name: cfg: [
# Create parent directories if they don't exist (root-owned, standard perms)
"d ${dirOf cfg.dataDir} 0755 root root -"
# Create service-owned directories
"d ${cfg.dataDir} 0750 ${cfg.user} ${cfg.group} -"
"d ${cfg.dataDir}/git 0750 ${cfg.user} ${cfg.group} -"
"d ${cfg.dataDir}/relay 0750 ${cfg.user} ${cfg.group} -"