# Volatile /run entries that must exist before vacuum-walld spawns. # # vacuum-walld runs with ProtectSystem=strict and lists these paths in # ReadWritePaths=; if a ReadWritePaths= entry is missing at spawn time, # systemd's mount-namespace setup fails (exit 226/NAMESPACE) and the unit # crash-loops without ever creating data/daemon.sock. /run is a fresh tmpfs # at every boot, so every /run path the unit references needs a boot-time # creator. Status per path: # # /run/vacuum-wall, /run/nginx -> unit RuntimeDirectory= (daemon-owned) # /run/firewalld -> this file (the firewalld unit only creates # it while firewalld itself is running) # /run/nginx.pid -> this file (nginx rewrites it on start; the # daemon's `nginx -t` must be able to open # it for writing inside its ProtectSystem=strict # namespace, so it needs both a boot-time # creator and a ReadWritePaths= entry) # /run/sudo -> not referenced by the unit (see # ReadWritePaths note in vacuum-walld.service); # the sudo package ships its own tmpfiles spec # # Applied at early boot by systemd-tmpfiles-setup.service and by the install # script (`systemd-tmpfiles --create`) for existing hosts. d /run/firewalld 0750 root root - f /run/nginx.pid 0644 root root -