Install MTProxy readable and executable by its service user. - #2
Open
tral wants to merge 1 commit into
Open
Conversation
install.sh sets umask 077 and install-mtproxy.sh inherits it, so make created objs/ and objs/bin/ as 0700 and the built binary as 0700. After the tree is chowned to root, the unprivileged mtproxy user that mtproxy.service runs as can neither traverse the directories nor execute the binary, and the unit fails with status=203/EXEC on every clean build. Apply a+rX to the installed tree. This runs outside the build guard so it also repairs a tree left behind by an earlier run, which the pinned-commit check would otherwise skip. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
scribernickie6-ui
approved these changes
Aug 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
install.sh sets umask 077 and install-mtproxy.sh inherits it, so make created objs/ and objs/bin/ as 0700 and the built binary as 0700. After the tree is chowned to root, the unprivileged mtproxy user that mtproxy.service runs as can neither traverse the directories nor execute the binary, and the unit fails with status=203/EXEC on every clean build.
Apply a+rX to the installed tree. This runs outside the build guard so it also repairs a tree left behind by an earlier run, which the pinned-commit check would otherwise skip.