~ruther/guix-local

5db599f41a14550ea2595e2caed966d75bcd8ae6 — Ivan Popovych 1 year, 4 months ago dd7e39c
etc: guix-daemon.service.in: Disable host filesystem mount propagation.

This fixes issue for rootless guix daemon where store being remounted
read-only by gnu-store.mount is propagated to the guix daemon making
guix daemon not able to modify it.

* etc/guix-daemon.service.in: Disable host filesystem mount propagation.

Change-Id: Ib1abc387ee15d2b04d6f70c121244943cd0ad8c6
Signed-off-by: Ludovic Courtès <ludo@gnu.org>
Modified-by: Ludovic Courtès <ludo@gnu.org>
1 files changed, 3 insertions(+), 0 deletions(-)

M etc/guix-daemon.service.in
M etc/guix-daemon.service.in => etc/guix-daemon.service.in +3 -0
@@ 21,6 21,9 @@ User=guix-daemon
# effect of 'gnu-store.mount'.
PrivateMounts=true
BindPaths=@storedir@
# Disable host file system mount propagation to keep service view of the
# store read-write after 'gnu-store.mount' makes it read-only system-wide.
MountFlags=private

# Provide the CAP_CHOWN capability so that guix-daemon can create and chown
# /var/guix/profiles/per-user/$USER and also chown failed build directories