privileged: Don't isolate /var/tmp/ for privileged daemon
-
Files from web service are uploaded to /var/tmp/ directory. They need to accessible to privileged daemon to that it can move them to a target location. So, if /var/tmp is isolated for privileged daemon, it can't see those files as a separate tmpfs filesystem is mounted on that folder.
-
Ideally, we should have PrivateTmp=yes and JoinsNameSpacesOf=freedombox-privileged.service set on plinth.service. However, this requires further changes to the way developer execution is done command line. This is done in future.
Tests:
-
Uploading a backup works.
-
Uploading a kiwix archive works.
Signed-off-by: Sunil Mohan Adapa sunil@medhas.org