[00:01:21]
<Yunohost Git/Infra notifications> [yunohost] zamentur pushed 9 commits to umask_fixes ([8954b33208ef...0e7532b5cd8c](https://github.com/YunoHost/yunohost/compare/8954b33208ef...0e7532b5cd8c))
[00:21:30]
<Yunohost Git/Infra notifications> [yunohost] zamentur [commented](https://github.com/YunoHost/yunohost/pull/2351#discussion_r3890718010) on pull request #2351 [fix] No SSH with public key after trixie migration: If i remember well, in bookworm, .ssh and .ssh/authorized_keys was already checked by sshd. SO the issue with trixie...
[14:02:33]
<Yunohost Git/Infra notifications> [issues] fflorent edited [issue #2837](https://github.com/YunoHost/issues/issues/2837) : Trixie migration: 0037_postgresql_15_to_17 fails cause postgresql is already on 18
[14:02:35]
<Yunohost Git/Infra notifications> [issues] fflorent edited [issue #1651](https://github.com/YunoHost/issues/issues/1651) : Postgresql migration failed due to Postgis during major Debian upgrades
[17:39:20]
<tituspijean[m]> @josue:tille.ch @ljf:sans-nuage.fr pinging you since you are working on the file permissions.
Disclaimer: I might have a frankenserver after so many tests.
Right now nftables fails to start upon boot. I had to add a TimeoutSec in rescue mode to unblock it.
Here are the errors (in french):
```
Aug 31 18:04:48 yunohost-nftables-hooks[1378]: /usr/local/bin/lxd-network-sync: ligne 32: /etc/dnsmasq.d/lxd: Système de fichiers accessible en lecture seulement
Aug 31 18:04:48 yunohost-nftables-hooks[1382]: chmod: modification des droits de '/etc/dnsmasq.d/lxd': Système de fichiers accessible en lecture seulement
```
When manually starting it up it works, with this error:
```
yunohost-nftables-hooks[6195]: Error: mkdir /root/.config: read-only file system
```
I can safely say my server is NOT read-only 😅
More info on the dnsmasq config:
```
ls -ld /etc
drwxr-xr-x 1 root root 4308 Aug 31 19:30 /etc
ls -ld /etc/dnsmasq.d/
drwxr-x--- 1 root root 2018 Aug 31 18:14 /etc/dnsmasq.d/
ls -ld /etc/dnsmasq.d/lxd
-rw-r----- 1 root root 115 Aug 23 10:01 /etc/dnsmasq.d/lxd
```
[18:08:17]
<Yunohost Git/Infra notifications> [yunohost] fflorent [commented](https://github.com/YunoHost/yunohost/pull/2351#discussion_r3897075674) on pull request #2351 [fix] No SSH with public key after trixie migration: Actually, on bookworm, setting write permission for other to either /home/USER, .ssh or .ssh/authorized_keys mak...
[18:08:45]
<Yunohost Git/Infra notifications> [yunohost] fflorent edited a [comment](https://github.com/YunoHost/yunohost/pull/2351#discussion_r3897075674) on pull request #2351 [fix] No SSH with public key after trixie migration: Actually, on bookworm, setting write permission for other to either /home/USER, .ssh or .ssh/authorized_keys mak...
[18:09:26]
<Yunohost Git/Infra notifications> [yunohost] fflorent edited a [comment](https://github.com/YunoHost/yunohost/pull/2351#discussion_r3897075674) on pull request #2351 [fix] No SSH with public key after trixie migration: Actually, I have just checked right now thanks to incus: - on bookworm, setting write permission for other to either ...
[18:09:47]
<Yunohost Git/Infra notifications> [yunohost] fflorent edited a [comment](https://github.com/YunoHost/yunohost/pull/2351#discussion_r3897075674) on pull request #2351 [fix] No SSH with public key after trixie migration: Actually, I have just checked right now thanks to incus: - on bookworm, setting write permission for other to either ...
[18:10:30]
<Yunohost Git/Infra notifications> [yunohost] fflorent edited a [comment](https://github.com/YunoHost/yunohost/pull/2351#discussion_r3897075674) on pull request #2351 [fix] No SSH with public key after trixie migration: Actually, I have just checked right now thanks to incus: - on bookworm, setting write permission for other to either ...
[18:16:15]
<Yunohost Git/Infra notifications> [yunohost] fflorent edited a [comment](https://github.com/YunoHost/yunohost/pull/2351#discussion_r3897075674) on pull request #2351 [fix] No SSH with public key after trixie migration: Actually, I have just checked right now thanks to incus: - on bookworm, setting write permission for other to either ...
[19:30:17]
<Yunohost Git/Infra notifications> [issues] orhtej2 opened [issue #2872](https://github.com/YunoHost/issues/issues/2872) : goenv v2 is superseded by v3
[20:48:02]
<Yunohost Git/Infra notifications> [yunohost] tituspijean [commented](https://github.com/YunoHost/yunohost/pull/2344#discussion_r3898153118) on pull request #2344 Improve file rights: /etc/resolv.dnsmasq.conf, even though dnsmasq runs as root, needs a visitors permission on my server: # chmod u=r...
[20:48:04]
<Yunohost Git/Infra notifications> [yunohost] tituspijean edited a [comment](https://github.com/YunoHost/yunohost/pull/2344#discussion_r3898153118) on pull request #2344 Improve file rights: /etc/resolv.dnsmasq.conf, even though dnsmasq runs as root, needs an Others permission on my server: # chmod u=rw...
[20:48:08]
<tituspijean[m]> (I rescind my previous message where I pinged josu-e and lj-f, I cannot replicate the issue)
[20:48:10]
<Yunohost Git/Infra notifications> [yunohost] zamentur edited a [comment](https://github.com/YunoHost/yunohost/pull/2351#discussion_r3836011482) on pull request #2351 [fix] No SSH with public key after trixie migration: Its not only the user home directory that has to be g-w,o-w, but also the .ssh/ directory and the .ssh/authorized_...
[20:53:22]
<Yunohost Git/Infra notifications> [moulinette] zamentur pushed to fix-umask: [fix] Ensure default umask is set before running request ([a386461f](https://github.com/YunoHost/moulinette/commit/a386461faca8306989187fdf9e14eb4afe6aa649))
[20:54:09]
<Yunohost Git/Infra notifications> [moulinette] zamentur opened [pull request #383](https://github.com/YunoHost/moulinette/pull/383) : [fix] Ensure default umask is set before running request
[20:55:40]
<Yunohost Git/Infra notifications> [yunohost] zamentur edited [pull request #2344](https://github.com/YunoHost/yunohost/pull/2344) : Improve file rights
[20:57:17]
<Yunohost Git/Infra notifications> [yunohost] zamentur [commented](https://github.com/YunoHost/yunohost/pull/2344#issuecomment-5484456758) on [issue #2344](https://github.com/YunoHost/yunohost/pull/2344) Improve file rights: I just add a mechanism to force umask to 0o022 before each requests, like that if we have an other issue like that, the ...
[20:58:19]
<Yunohost Git/Infra notifications> [yunohost] zamentur pushed to umask_fixes: [fix] Ensure default umask 0o022 is set before running request ([a5c11cf2](https://github.com/YunoHost/yunohost/commit/a5c11cf248c994fc92c04083a04aaa4953509d7f))
[22:29:48]
<Yunohost Git/Infra notifications> [yunohost] zamentur [commented](https://github.com/YunoHost/yunohost/pull/2344#discussion_r3898927847) on pull request #2344 Improve file rights: Good catch By default DNSMASQ_USER=dnsmasq so the service run this command (i checked that with systemctl status dns...
[22:29:49]
<Yunohost Git/Infra notifications> [yunohost] zamentur edited [pull request #2344](https://github.com/YunoHost/yunohost/pull/2344) : Improve file rights