<p dir="ltr">Hello,</p>
<p dir="ltr">Isn't there UID mapping support for this purpose? For that specific NFS mount, you could map whatever UID it is to UID 0</p>
<p dir="ltr">Best,<br>
Adrian </p>
<br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Thu, Mar 27, 2025, 15:03 James Muir (jamesmui) <<a href="mailto:jamesmui@cisco.com">jamesmui@cisco.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div lang="EN-CA" link="#467886" vlink="#96607D" style="word-wrap:break-word">
<div class="m_6441784459194281163WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt">> > Is there a conf option or an environment variable I can use to disable the unsafe path transition check?<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">> <u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">> No there is not. It's a security hole what you are doing there...<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">> <u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">> > Failing that, is there a way I can change the ownership systemd-tmpfiles sees?<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">> <u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">> Why not just fix the ownership of the root inode? i.e. actually fix<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">> the original problem that causes the message to show?<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">The root filesystem is mounted read-only because the nfs server only allows read-only exports (i.e. "ro").<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">So, "chown root:root /" does not work on the client.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">And on the server, I do not have root access.<u></u><u></u></span></p>
<div id="m_6441784459194281163mail-editor-reference-message-container">
<div>
<div>
<div>
<p class="MsoNormal"><b><span style="font-size:12.0pt"><u></u> <u></u></span></b></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote></div>