Skip to content

Fix systemd service to run with native root privileges - #1

Merged
Sbgodin merged 2 commits into
mainfrom
copilot/check-system-service-setup
May 27, 2026
Merged

Sbgodin merged 2 commits into
mainfrom
copilot/check-system-service-setup

Conversation

Copilot AI commented Feb 18, 2026 •

Copy link
Copy Markdown
Contributor

The systemd service configuration incorrectly used privilege escalation prefix and sudo commands, preventing proper execution of cryptsetup/mount operations.

Changes

  • filurn.service: Removed + prefix from ExecStart directive
  • filurn-mount.sh: Removed sudo from all commands (umount, cryptsetup, mkfs, mount, rmdir, touch)

Context

Systemd services run as root by default. The + prefix is for privilege escalation from a non-root user context, which doesn't apply here. The sudo commands would fail in service context due to lack of TTY and authentication unavailability.

[Service]
Type=simple
-ExecStart=+/usr/local/bin/filurn/filurnd.sh
+ExecStart=/usr/local/bin/filurn/filurnd.sh
-sudo cryptsetup open --type plain --cipher aes-xts-plain64 --key-file /dev/urandom "$DISK" "$NAME"
+cryptsetup open --type plain --cipher aes-xts-plain64 --key-file /dev/urandom "$DISK" "$NAME"
Original prompt

Is this project correctly built as a system service ?


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

Co-authored-by: Sbgodin <3691603+Sbgodin@users.noreply.github.com>
Copilot AI changed the title [WIP] Verify project setup as a system service Fix systemd service to run with native root privileges Feb 18, 2026
Copilot AI requested a review from Sbgodin February 18, 2026 06:11
@Sbgodin
Sbgodin marked this pull request as ready for review May 27, 2026 04:50
Copilot AI review requested due to automatic review settings May 27, 2026 04:50
@Sbgodin
Sbgodin merged commit 694102f into main May 27, 2026
1 check failed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adjusts Filurn’s systemd/service execution model to rely on systemd’s native root execution rather than in-command privilege escalation, so cryptsetup/mount-related operations can run correctly in a service context.

Changes:

  • Removed the + execution prefix from the systemd unit’s ExecStart.
  • Removed sudo from privileged commands in filurn-mount.sh (umount/cryptsetup/mkfs/mount/etc.).

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
filurn.service Simplifies ExecStart by removing the + prefix so the service runs normally under systemd.
filurn-mount.sh Removes sudo usage so privileged operations run directly when invoked by the root-run service.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread filurn-mount.sh
Comment on lines +9 to +12
umount $MAPPER
cryptsetup close $MAPPER

sudo cryptsetup open --type plain --cipher aes-xts-plain64 --key-file /dev/urandom "$DISK" "$NAME"
cryptsetup open --type plain --cipher aes-xts-plain64 --key-file /dev/urandom "$DISK" "$NAME"
@Sbgodin
Sbgodin deleted the copilot/check-system-service-setup branch May 27, 2026 04:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants