git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH 1/5] maintenance: package systemd units

From
Max Gautier <mg@max.gautier.name>
Date
Mar 21, 2024, 13:07 UTC
Message-ID
<Zfww9jI2em6ZY4SL@framework>
In-Reply-To
<ZfwqCv889UdI0mU6@tanuki>
On Thu, Mar 21, 2024 at 01:37:30PM +0100, Patrick Steinhardt wrote:
Show 5 quoted lines
> On Mon, Mar 18, 2024 at 04:31:15PM +0100, Max Gautier wrote:
> 
> It would be great to document _why_ we want to package the systemd units
> alongside with Git.
> 

Hum, I wrote that in the cover, but you're right, it should be in the commit itself. Ack.

Show 28 quoted lines
> > ...
> > diff --git a/systemd/user/git-maintenance@.service b/systemd/user/git-maintenance@.service
> > new file mode 100644
> > index 0000000000..87ac0c86e6
> > --- /dev/null
> > +++ b/systemd/user/git-maintenance@.service
> > @@ -0,0 +1,16 @@
> > +[Unit]
> > +Description=Optimize Git repositories data
> > +
> > +[Service]
> > +Type=oneshot
> > +ExecStart=git for-each-repo --config=maintenance.repo \
> > +          maintenance run --schedule=%i
> > +LockPersonality=yes
> > +MemoryDenyWriteExecute=yes
> > +NoNewPrivileges=yes
> > +RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_VSOCK
> > +RestrictNamespaces=yes
> > +RestrictRealtime=yes
> > +RestrictSUIDSGID=yes
> > +SystemCallArchitectures=native
> > +SystemCallFilter=@system-service
> 
> Curious, but how did you arrive at these particular restrictions for the
> unit? Might be something to explain in the commit message, as well.
> 
> Patrick

I copied the unit file which is defined in strings in builtin/gc.c, which I delete in patch 3. Should the moving be inside one commit, in order to explicit the fact that it's only moving things around ?

-- 
Max Gautier
Previous: Patrick SteinhardtNext: Patrick Steinhardt
Message 4 of 22 in “maintenance: use packaged systemd units”
  1. 0/5 maintenance: use packaged systemd unitsMax Gautier, Mar 18, 2024
  2. 1/5 maintenance: package systemd unitsMax Gautier, Mar 18, 2024
  3. Patrick SteinhardtMar 21, 2024
  4. Max GautierMar 21, 2024
  5. Patrick SteinhardtMar 21, 2024
  6. Max GautierMar 21, 2024
  7. Patrick SteinhardtMar 21, 2024
  8. Max GautierMar 21, 2024
  9. Max GautierMar 21, 2024
  10. 2/5 maintenance: add fixed random delay to systemd timersMax Gautier, Mar 18, 2024
  11. Patrick SteinhardtMar 21, 2024
  12. Max GautierMar 21, 2024
  13. 4/5 maintenance: update systemd scheduler docsMax Gautier, Mar 18, 2024
  14. Patrick SteinhardtMar 21, 2024
  15. 3/5 maintenance: use packaged systemd unitsMax Gautier, Mar 18, 2024
  16. Max GautierMar 19, 2024
  17. Eric SunshineMar 19, 2024
  18. Junio C HamanoMar 19, 2024
  19. Max GautierMar 19, 2024
  20. Patrick SteinhardtMar 21, 2024
  21. Max GautierMar 21, 2024
  22. 5/5 DON'T APPLY YET: maintenance: remove cleanup codeMax Gautier, Mar 18, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.