From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp0 ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms0.migadu.com with LMTPS id iDo9FMGV4GCOwQAAgWs5BA (envelope-from ) for ; Sat, 03 Jul 2021 18:52:17 +0200 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp0 with LMTPS id 4w3pD8GV4GDpRgAA1q6Kng (envelope-from ) for ; Sat, 03 Jul 2021 16:52:17 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id D4D7716405 for ; Sat, 3 Jul 2021 18:52:16 +0200 (CEST) Received: from localhost ([::1]:60776 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1lzisJ-0002E5-Tl for larch@yhetil.org; Sat, 03 Jul 2021 12:52:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:57096) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lzis5-0002Dh-Ub for guix-patches@gnu.org; Sat, 03 Jul 2021 12:52:01 -0400 Received: from debbugs.gnu.org ([209.51.188.43]:56448) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1lzis5-0006UX-NY for guix-patches@gnu.org; Sat, 03 Jul 2021 12:52:01 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1lzis5-0006Pk-LC for guix-patches@gnu.org; Sat, 03 Jul 2021 12:52:01 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#44700] [PATCH v2 0/2] services: setuid: More configurable setuid support. Resent-From: Brice Waegeneire Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sat, 03 Jul 2021 16:52:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 44700 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: To: 44700@debbugs.gnu.org Cc: cwebber@dustycloud.org Received: via spool by 44700-submit@debbugs.gnu.org id=B44700.162533110124553 (code B ref 44700); Sat, 03 Jul 2021 16:52:01 +0000 Received: (at 44700) by debbugs.gnu.org; 3 Jul 2021 16:51:41 +0000 Received: from localhost ([127.0.0.1]:39757 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lzirk-0006Nx-P1 for submit@debbugs.gnu.org; Sat, 03 Jul 2021 12:51:40 -0400 Received: from relay10.mail.gandi.net ([217.70.178.230]:39603) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lzirg-0006NX-O5 for 44700@debbugs.gnu.org; Sat, 03 Jul 2021 12:51:39 -0400 Received: (Authenticated sender: brice@waegenei.re) by relay10.mail.gandi.net (Postfix) with ESMTPSA id E5871240007; Sat, 3 Jul 2021 16:51:29 +0000 (UTC) From: Brice Waegeneire Date: Sat, 3 Jul 2021 18:51:25 +0200 Message-Id: <20210703165127.12316-1-brice@waegenei.re> X-Mailer: git-send-email 2.31.1 In-Reply-To: <87v98o94ob.fsf@dustycloud.org> References: <87v98o94ob.fsf@dustycloud.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: "Guix-patches" X-Migadu-Flow: FLOW_IN ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1625331137; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding:resent-cc: resent-from:resent-sender:resent-message-id:in-reply-to:in-reply-to: references:references:list-id:list-help:list-unsubscribe: list-subscribe:list-post; bh=+7Eg7Fi1RFrlpXf2b/oJTi8lh8bUF3YELyeJCPV6F4g=; b=PG5aKOQAC5rmIYcVw7ooDeWASKLPLRYOMduri7SC6/aW8/ZaDUP4VwhNDTC9y+16Cm26Id culifoxIQys4/y/AVM+q0WxQhjBsi37+YKy3oXV15opi4urQWQrEdGK1jXyjySNub62bqk vuPWfztXnhqE73NDKeyWiWpeaXZ0yuaL4SmH4VSO6bRicsPza4zOf7o4Umab+0onEeh87o JnhERF+pReitYHUBAwSrNoUUYOMwSKkJBa+y+5BwMgUc4VeNF/ewATuMzR/kgX/3Wc/whN 86p2pqyYse2+NrSDys/Pd6HQRVwYavmQz7Yias5FIp+cRmH7gxqas/4+zohZXg== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1625331137; a=rsa-sha256; cv=none; b=kvhZn8ixMNG0nYx6nEGDD4E1rTDmJZlSVfFVoHUjUkq92DAKTM3zPyjknZZtZ2pYf4QpFF qooeyi1eeJG+OfRrUGziRPu60WrNHhG6rpTqlQzsRJH69Yq0lLLIvY7YnMVmPFQhU+ZxAe WFGkH1IYpV8SvmPXvtqd0Wo1ZUgseTzF6Wf/kWh9jIS65nt1YwrrbPC6Iq4fa4FKmTPzzX vvZVpUBjwc703ukn2wbXJit0bHpakFl7ZpnzE9dgR7m0pPdVpJ2rjIykc4dp6aKGa2yH9v CMH1G2Hqp+xy/kFxpiQgj1QNmCtZLW+IK6cMhcam3HpuRRlCnp7d0EY4Omcf9w== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=none; dmarc=none; spf=pass (aspmx1.migadu.com: domain of guix-patches-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-patches-bounces@gnu.org X-Migadu-Spam-Score: 2.59 Authentication-Results: aspmx1.migadu.com; dkim=none; dmarc=none; spf=pass (aspmx1.migadu.com: domain of guix-patches-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-patches-bounces@gnu.org X-Migadu-Queue-Id: D4D7716405 X-Spam-Score: 2.59 X-Migadu-Scanner: scn1.migadu.com X-TUID: 7Yxt6Y1Wn1HD Hello Christopher, Some times ago I continued your patch from where you left it. If I recall correctly it should address all the suggestions from Ludo' and Maxim. I'm using it for several month now without any issue. Thank your for your work on this issue Christopher! Cheers, - Brice Brice Waegeneire (1): services: Migrate to . Christopher Lemmer Webber (1): services: setuid: More configurable setuid support. gnu/build/activation.scm | 38 ++++++++++++++++++++------- gnu/services.scm | 45 ++++++++++++++++++++++++++++--- gnu/services/dbus.scm | 13 ++++++--- gnu/services/desktop.scm | 26 +++++++++++------- gnu/services/docker.scm | 9 ++++--- gnu/services/xorg.scm | 4 ++- gnu/system.scm | 45 +++++++++++++++++-------------- gnu/system/setuid.scm | 57 ++++++++++++++++++++++++++++++++++++++++ 8 files changed, 186 insertions(+), 51 deletions(-) create mode 100644 gnu/system/setuid.scm -- 2.31.1