Do not protect /home.

This commit is contained in:
Andrea Dell'Amico 2026-09-22 16:53:32 +02:00
parent 34d4809921
commit 858cdc4b1b
Signed by: adellam
GPG Key ID: 147ABE6CEB9E20FF
2 changed files with 16 additions and 5 deletions

View File

@ -118,13 +118,21 @@ forgejo_systemd_hardening_file: '/etc/systemd/system/{{ forgejo_service_name }}.
forgejo_systemd_read_write_paths: []
# Paths to hide from the service entirely (InaccessiblePaths=)
forgejo_systemd_inaccessible_paths: []
# ProtectHome= empties /home, /root and /run/user. It is safe ONLY while the
# builtin SSH server is in use: forgejo then never writes
# <git_home>/.ssh/authorized_keys (models/asymkey returns immediately when
# START_SSH_SERVER is on) and only reads $HOME, which it never stats.
# ProtectHome= hides /home, /root and /run/user. Two things decide the value:
#
# * 'tmpfs' and NOT 'true', because the postgres driver looks for client
# certificates in $HOME/.postgresql/ on every TLS connection. With 'true'
# that stat returns EACCES and forgejo dies with
# "stat /home/git/.postgresql/postgresql.crt: permission denied", after ten
# connection attempts that say nothing about systemd. 'tmpfs' gives the
# same empty home and answers ENOENT, which the driver ignores.
# * hiding the home at all is safe ONLY while the builtin SSH server is in
# use: forgejo then never writes <git_home>/.ssh/authorized_keys
# (models/asymkey returns immediately when START_SSH_SERVER is on).
#
# ReadWritePaths= does NOT punch a hole through ProtectHome= (verified on
# systemd 255), so with system sshd serving git this has to be false.
forgejo_systemd_protect_home: "{{ 'true' if (server_START_SSH_SERVER | default('true') | bool) else 'false' }}"
forgejo_systemd_protect_home: "{{ 'tmpfs' if (server_START_SSH_SERVER | default('true') | bool) else 'false' }}"
# PrivateUsers= maps only root and the service user; every other uid becomes
# nobody. Turn it off if forgejo has to reach a file owned by a third user, or
# if the service user needs supplementary groups.

View File

@ -20,6 +20,9 @@ CapabilityBoundingSet=
# The whole filesystem read only except the paths below. Every one of them must
# exist, or systemd fails the namespace and forgejo never starts (226/NAMESPACE).
ProtectSystem=strict
# 'tmpfs' rather than 'true': an empty home either way, but a missing file
# under it answers ENOENT instead of EACCES, and the postgres driver stats
# $HOME/.postgresql/postgresql.crt on every TLS connection.
ProtectHome={{ forgejo_systemd_protect_home }}
ReadWritePaths={{ ([forgejo_work_dir, forgejo_repository_data] + forgejo_systemd_read_write_paths) | unique | map('quote') | join(' ') }}
{% if forgejo_systemd_inaccessible_paths | length > 0 %}