Commit 941c24f
authored
fix: expand tmpfiles.d for MTA services (CO-2524) (#44)
* fix: expand tmpfiles.d for MTA services (CO-2524)
Expand systemd-tmpfile.conf from 4 to 50 lines (+1,150%) as part of
zmfixperms replacement. Provides declarative directory management for
all MTA-related services.
Changes:
- Add postfix master and main configuration files
- Add postfix bysender database files
- Add postfix RE files (tag_as_foreign, tag_as_originating)
- Add virtual domain configuration files with postfix group access
- Add postfix setgid binaries (postqueue, postdrop) with mode 2755
- Add postfix data directory structure
- Add postfix spool directories with special permissions:
* public: 0710 (postfix:postdrop)
* maildrop: 0730 (postfix:postdrop)
- Add amavisd directories (anti-spam/anti-virus)
- Add spamassassin data directories
- Add altermime directory (MIME message modifier)
- Add cbpolicyd directories (postfix policy daemon)
Post-install requirements documented in comments:
- Recursive permission removal on data directory (chmod -R go-w)
- Recursive ownership change on spool directory (chown -fR)
- Additional spool subdirectories created at runtime by postfix
SELinux support:
- Automatic context restoration via 'z' directives (lines 2-24)
- No manual chcon/restorecon needed
Addresses CO-2524 (IN-754): Replace zmfixperms with tmpfiles.d
* fix: call systemd-tmpfiles with specific config file (CO-2524)
Change from:
systemd-tmpfiles --create
To:
systemd-tmpfiles --create /usr/lib/tmpfiles.d/carbonio-mta.conf
Benefits:
- Only processes this package's tmpfiles.d configuration
- Avoids redundant processing of other packages' configs
- Faster execution during package installation
- Clear separation of concerns between packages
This prevents each package from reprocessing all tmpfiles.d configs
in /usr/lib/tmpfiles.d/ during postinst, which was inefficient when
packages have dependency relationships.
* refactor: move ClamAV directory to carbonio-clamav package (CO-2524)
Remove ClamAV data directory management from carbonio-mta tmpfiles.d
configuration as it's now handled by carbonio-clamav package directly.
Changes:
- Remove /opt/zextras/data/clamav/db entry from systemd-tmpfile.conf
- Update PKGBUILD checksum for systemd-tmpfile.conf
This follows the principle that packages should manage their own
directories. The carbonio-clamav package now includes its own
tmpfiles.d configuration for its data directory.
Related to CO-2524 (IN-754) - tmpfiles.d migration
* refactor: move third-party directories to respective packages (CO-2524)
Remove amavisd, spamassassin, and cbpolicyd directory management
from carbonio-mta as these are now handled by their respective
third-party packages.
Changes:
- Removed 4 amavisd/spamassassin entries (lines 39-43)
- Removed 2 cbpolicyd entries (lines 51-53)
- Reduced from 58 to 48 lines
- Updated PKGBUILD checksum
Directories moved to:
- carbonio-amavisd: /opt/zextras/data/amavisd/*
- carbonio-perl-mail-spamassassin: /opt/zextras/data/spamassassin, /var/spamassassin
- carbonio-policyd: /opt/zextras/data/cbpolicyd/*
Kept in carbonio-mta:
- /opt/zextras/data/opendkim (carbonio-opendkim doesn't create it)
- /opt/zextras/data/altermime (carbonio-altermime doesn't create it)
Related to CO-2524 (IN-754) - tmpfiles.d migration
* refactor: move postfix directories to carbonio-postfix (CO-2524)
Removes postfix directory management from carbonio-mta - these are now
handled by carbonio-postfix package via its own tmpfiles.d and sysusers.d.
Changes:
- Removed postfix directory definitions (lines 27-37, -11 lines)
- Removed postfix-related notes (lines 45-48, -4 lines)
- Kept MTA-owned config file permissions (master.cf.in, bysender, RE files,
virtual domain configs)
- Updated checksum
Package boundaries:
- carbonio-postfix: Manages postfix users, groups, base directories, SGID binaries
- carbonio-mta: Manages MTA-specific config files that need group postfix access
Code reduction:
- Before: 49 lines → After: 33 lines (-16 lines, -33%)
Related: CO-2524, IN-754
* fix: correct sysusers.d syntax for carbonio-mta group (CO-2524)
The group definition had incorrect syntax with too many fields:
g carbonio-mta - - - "carbonio mta group"
This caused systemd-sysusers to fail with error:
'carbonio mta group' is not a valid login shell field
The correct sysusers.d group format is:
g NAME ID
Fixed by removing extra fields and adding comments for clarity.
Fixes:
- carbonio-mta user/group creation failure
- carbonio-core post-install failure (exit code 73)
- systemd-sysusers processing errors
Impact: Critical - blocks proper package installation
* fix: silence systemd-sysusers and tmpfiles to prevent postinst failures (CO-2524)
* fix: remove redundant mkdir/chown from postinst scripts
Directory creation for amavisd, clamav, opendkim, postfix is now
handled by their respective packages' tmpfiles.d configurations:
- carbonio-amavisd: /opt/zextras/data/amavisd/*
- carbonio-clamav: /opt/zextras/data/clamav/db
- carbonio-postfix: /opt/zextras/data/postfix/*
- carbonio-mta: /opt/zextras/data/opendkim, altermime
This removes ~100 lines of duplicate directory setup code from
all 4 postinst functions.
* chore: add SPDX license headers to systemd configs
Add SPDX-FileCopyrightText and SPDX-License-Identifier headers
to sysusers.d and tmpfiles.d configurations for license compliance.
Updated PKGBUILD checksums accordingly.1 parent 523539b commit 941c24f
3 files changed
+76
-160
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
| 64 | + | |
| 65 | + | |
64 | 66 | | |
65 | 67 | | |
66 | 68 | | |
| |||
75 | 77 | | |
76 | 78 | | |
77 | 79 | | |
| 80 | + | |
| 81 | + | |
78 | 82 | | |
79 | 83 | | |
80 | 84 | | |
81 | 85 | | |
82 | 86 | | |
83 | 87 | | |
84 | | - | |
| 88 | + | |
85 | 89 | | |
86 | | - | |
| 90 | + | |
87 | 91 | | |
88 | | - | |
| 92 | + | |
89 | 93 | | |
90 | | - | |
| 94 | + | |
91 | 95 | | |
92 | | - | |
| 96 | + | |
93 | 97 | | |
94 | | - | |
| 98 | + | |
95 | 99 | | |
96 | | - | |
| 100 | + | |
97 | 101 | | |
98 | 102 | | |
99 | 103 | | |
| |||
111 | 115 | | |
112 | 116 | | |
113 | 117 | | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
114 | 125 | | |
115 | 126 | | |
116 | 127 | | |
117 | | - | |
| 128 | + | |
118 | 129 | | |
119 | 130 | | |
120 | 131 | | |
| |||
161 | 172 | | |
162 | 173 | | |
163 | 174 | | |
164 | | - | |
165 | | - | |
166 | | - | |
167 | | - | |
168 | | - | |
169 | | - | |
170 | | - | |
171 | | - | |
172 | | - | |
173 | | - | |
174 | | - | |
175 | | - | |
176 | | - | |
177 | | - | |
178 | | - | |
179 | | - | |
180 | | - | |
181 | | - | |
182 | | - | |
183 | | - | |
184 | | - | |
185 | | - | |
186 | | - | |
187 | | - | |
188 | | - | |
189 | | - | |
| 175 | + | |
190 | 176 | | |
191 | 177 | | |
192 | 178 | | |
| |||
200 | 186 | | |
201 | 187 | | |
202 | 188 | | |
203 | | - | |
204 | | - | |
205 | | - | |
206 | | - | |
207 | | - | |
208 | | - | |
209 | | - | |
210 | | - | |
211 | | - | |
212 | | - | |
213 | | - | |
214 | | - | |
| 189 | + | |
| 190 | + | |
215 | 191 | | |
216 | 192 | | |
217 | 193 | | |
| |||
239 | 215 | | |
240 | 216 | | |
241 | 217 | | |
242 | | - | |
243 | | - | |
244 | | - | |
245 | | - | |
246 | | - | |
247 | | - | |
248 | | - | |
249 | | - | |
250 | | - | |
251 | | - | |
252 | | - | |
253 | | - | |
254 | | - | |
255 | | - | |
256 | | - | |
257 | | - | |
258 | | - | |
259 | | - | |
260 | | - | |
261 | | - | |
262 | | - | |
263 | | - | |
264 | | - | |
265 | | - | |
266 | | - | |
267 | | - | |
| 218 | + | |
268 | 219 | | |
269 | 220 | | |
270 | 221 | | |
| |||
278 | 229 | | |
279 | 230 | | |
280 | 231 | | |
281 | | - | |
282 | | - | |
283 | | - | |
284 | | - | |
285 | | - | |
286 | | - | |
287 | | - | |
288 | | - | |
289 | | - | |
290 | | - | |
291 | | - | |
292 | | - | |
| 232 | + | |
| 233 | + | |
293 | 234 | | |
294 | 235 | | |
295 | 236 | | |
| |||
304 | 245 | | |
305 | 246 | | |
306 | 247 | | |
307 | | - | |
308 | | - | |
309 | | - | |
310 | | - | |
311 | | - | |
312 | | - | |
313 | | - | |
314 | | - | |
315 | | - | |
316 | | - | |
317 | | - | |
318 | | - | |
319 | | - | |
320 | | - | |
321 | | - | |
322 | | - | |
323 | | - | |
324 | | - | |
325 | | - | |
326 | | - | |
327 | | - | |
328 | | - | |
329 | | - | |
330 | | - | |
331 | | - | |
332 | | - | |
| 248 | + | |
333 | 249 | | |
334 | 250 | | |
335 | 251 | | |
| |||
343 | 259 | | |
344 | 260 | | |
345 | 261 | | |
346 | | - | |
347 | | - | |
348 | | - | |
349 | | - | |
350 | | - | |
351 | | - | |
352 | | - | |
353 | | - | |
354 | | - | |
355 | | - | |
356 | | - | |
357 | | - | |
| 262 | + | |
| 263 | + | |
358 | 264 | | |
359 | 265 | | |
360 | 266 | | |
| |||
368 | 274 | | |
369 | 275 | | |
370 | 276 | | |
371 | | - | |
372 | | - | |
373 | | - | |
374 | | - | |
375 | | - | |
376 | | - | |
377 | | - | |
378 | | - | |
379 | | - | |
380 | | - | |
381 | | - | |
382 | | - | |
383 | | - | |
384 | | - | |
385 | | - | |
386 | | - | |
387 | | - | |
388 | | - | |
389 | | - | |
390 | | - | |
391 | | - | |
392 | | - | |
393 | | - | |
394 | | - | |
395 | | - | |
396 | | - | |
| 277 | + | |
397 | 278 | | |
398 | 279 | | |
399 | 280 | | |
| |||
407 | 288 | | |
408 | 289 | | |
409 | 290 | | |
410 | | - | |
411 | | - | |
412 | | - | |
413 | | - | |
414 | | - | |
415 | | - | |
416 | | - | |
417 | | - | |
418 | | - | |
419 | | - | |
420 | | - | |
421 | | - | |
| 291 | + | |
| 292 | + | |
422 | 293 | | |
423 | 294 | | |
424 | 295 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
0 commit comments