From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp10.migadu.com ([2001:41d0:8:6d80::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms9.migadu.com with LMTPS id aI15CQM2nWQsuQAASxT56A (envelope-from ) for ; Thu, 29 Jun 2023 09:42:59 +0200 Received: from aspmx1.migadu.com ([2001:41d0:8:6d80::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp10.migadu.com with LMTPS id IGVeCAM2nWT5fwEAG6o9tA (envelope-from ) for ; Thu, 29 Jun 2023 09:42:59 +0200 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 7548429ADA for ; Thu, 29 Jun 2023 09:42:58 +0200 (CEST) Authentication-Results: aspmx1.migadu.com; dkim=pass header.d=lendvai.name header.s=protonmail3 header.b=FjIasnD7; dmarc=none; spf=pass (aspmx1.migadu.com: domain of "guix-devel-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-devel-bounces+larch=yhetil.org@gnu.org" ARC-Seal: i=1; s=key1; d=yhetil.org; t=1688024579; a=rsa-sha256; cv=none; b=CooA60KT1aZAl0QTG04B0fkfbaQCN970W/ttFQQLqzbPDf5ee2+MlU2ckJdteplA1MzxCO /Pwvm6Eo9zY5CpE8v4R6fYPqrbdNwfBp8+nZ5A1yD12G8eSA+ixcX1s3hs8FlwvUN9+6WC HGvo6r1oeXMqWB006/VyDvRWUMNeq+C8teveB0R+3W5raTxBWVWgshevMlQ0AFE6sK63Jv 2X+PnvrRxLIbmiBtSW/wxq0QnqjjsGAWlLFX7AVuel0zzrBlgw44WWfhq2zbmsqGIPYZcV wieJdcqdHUmR0DPtfuldD2Pl0NG2i13EPhyzhx/Bk5x9md5ia1BYi1drl0dZWw== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=pass header.d=lendvai.name header.s=protonmail3 header.b=FjIasnD7; dmarc=none; spf=pass (aspmx1.migadu.com: domain of "guix-devel-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-devel-bounces+larch=yhetil.org@gnu.org" ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1688024579; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:list-id:list-help: list-unsubscribe:list-subscribe:list-post:dkim-signature; bh=cwSeQLzgORWtGsflCDrSeD9A0XNvoW6l2oMyI69x8MQ=; b=iN4cDq5yljVxcE+2E84R69Xa0fmomhq6laV5RjtmBmB2wIMePPWkRptf1xeO4Gr5ojBvzY Z1TvZfWgt38VCcz1DJ9w6rux608Bb1ntGlq2ON/3rO5alW6BLw/Iko0NO+2qY95h1E80bs n6BLcBLusT6D5GxTEjmacMg5Gem8I3EY69vTTxdNXqJGWuaq19j3SClM+KE2vVpwz4FCCf SwFXx7mUc1+lxfwvsqo7lEqdJ5A/SzjnQaVDIlSAivEigT0GyaO++a1UFU7XFGDI4wBZHy n7mCjDNs9MDL3zBl0qKDzZGCpeN4R5u4cjK2YsHd42mg5TzwRuUpZAsi5DwXfQ== Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1qEmIS-0001YT-02; Thu, 29 Jun 2023 03:42:35 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1qEmIL-0001Xv-MO for guix-devel@gnu.org; Thu, 29 Jun 2023 03:42:25 -0400 Received: from mail-4317.proton.ch ([185.70.43.17]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1qEmIH-0005n9-LI for guix-devel@gnu.org; Thu, 29 Jun 2023 03:42:25 -0400 Date: Thu, 29 Jun 2023 07:42:06 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lendvai.name; s=protonmail3; t=1688024537; x=1688283737; bh=cwSeQLzgORWtGsflCDrSeD9A0XNvoW6l2oMyI69x8MQ=; h=Date:To:From:Cc:Subject:Message-ID:In-Reply-To:References: Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID: Message-ID:BIMI-Selector; b=FjIasnD7r2sJtGNfP9tK5T5PVddN4qkFFVCVAb7QIlU6DWzhK+BYTbeK2KpWTkmK7 PHD6WMMPlcGOZIdukEfh/0YrtHg8oVLBpG63sjzf1GsnuQeIvTWoCuMcbskL8N6c3s L34yCBPaKXdNgLjQQBA2W7HNesAgmEwJfEHYsIUV3uMimPrV0N9IhRBhaCZNIiSaSQ 2No2oNp3MleUbUXu9Z+K8RdMjzecC7TB+ry80AJoRyOE89/jWzHNSS8F1G6fyCoHoc gMIk3/b2Y0WG5A0VrQihgQ0lJNreji5Stiu0ybEk70ylqsUaNA/E35dUSnJt85vV4Z 6YXuSrsF9Uowg== To: Felix Lechner From: Attila Lendvai Cc: guix-devel Subject: Re: shepherd service, unexplained permission errors Message-ID: In-Reply-To: References: Feedback-ID: 28384833:user:proton MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Received-SPF: pass client-ip=185.70.43.17; envelope-from=attila@lendvai.name; helo=mail-4317.proton.ch X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: guix-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+larch=yhetil.org@gnu.org Sender: guix-devel-bounces+larch=yhetil.org@gnu.org X-Migadu-Country: US X-Migadu-Flow: FLOW_IN X-Migadu-Scanner: scn1.migadu.com X-Migadu-Spam-Score: -5.81 X-Migadu-Queue-Id: 7548429ADA X-Spam-Score: -5.81 X-TUID: SkOmlzCZlgL+ thank you Felix! the broken expectation from me was that users "have" a group and supplement= ar-groups (as suggested by the (user-account #:group ...) constructor), and= if i specify the user to fork+exec-command, then it sets "its" group, too = (i tried with and without specifying a #:group). in retrospect it should have been obvious, because the fork+exec-command AP= I is on the abstraction level of linux, not that of guix. the solution that works now is essentially: (fork+exec-command cmd #:user "zigbee2mqtt" #:group '#$(user-account-group *zigbee2mqtt-user*) #:supplementary-groups '#$(user-account-supplementary-groups *zigbee2mqtt-user*)) thanks again, --=20 =E2=80=A2 attila lendvai =E2=80=A2 PGP: 963F 5D5F 45C7 DFCD 0A39 -- =E2=80=9CEnlightenment is man's leaving his self-caused immaturity. Immatur= ity is the incapacity to use one's intelligence without the guidance of ano= ther.=E2=80=9D =09=E2=80=94 Immanuel Kant (1724=E2=80=931804)