From ab1be6d042aba753dbb0041a0316ac3541c4daf2 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Wed, 16 Apr 2025 16:32:37 -0400 Subject: Fix /srv/syncthing ACLs Disable home directory creation, which clobbers directory permissions. Interestingly, after the ACLs are added the classic directory permissions appear as 770; but happily it works fine. Tip off was from https://discourse.nixos.org/t/home-facl-is-always-reset-in-21-05/13408 Also tried setting the ACL mask which wasn't the issue. --- hostnix/elmo/syncthing.nix | 16 +++++++++++----- 1 file changed, 11 insertions(+), 5 deletions(-) (limited to 'hostnix') diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix index 664179b..357179a 100644 --- a/hostnix/elmo/syncthing.nix +++ b/hostnix/elmo/syncthing.nix @@ -1,4 +1,6 @@ -{ ... }: +{ lib, ... }: + +# TODO iCloud bridge let staggeredVersioning = { @@ -15,16 +17,20 @@ in # difficult to grant granular access with classic permissions. systemd.tmpfiles.rules = let acls = builtins.concatStringsSep "," [ - "d:u:joe:rwX" - "u:joe:rwX" - "d:u:nginx:rX" - "u:nginx:rX" + "user:joe:rwX" + "default:user:joe:rwX" + "user:nginx:rX" + "default:user:nginx:rX" ]; in [ + "d /srv/syncthing 0700 syncthing syncthing" "A /srv/syncthing - - - - ${acls}" ]; + # Disable Syncthing service home creation which clobbers above permissions. + users.users.syncthing.createHome = lib.mkForce false; + services.syncthing = { enable = true; openDefaultPorts = true; -- cgit v1.3.1