dovecot: fix check for dovecot systemd unit name

and migrate the preStart script in systemd.nix as well.
This commit is contained in:
Martin Weinelt 2025-07-06 04:53:38 +02:00
parent a40574beb5
commit f9a52ca4b5
No known key found for this signature in database
GPG key ID: 87C1E9888F856759
2 changed files with 32 additions and 26 deletions

View file

@ -30,6 +30,26 @@ let
[ "mailserver-selfsigned-certificate.service" ]
else
[ "acme-finished-${cfg.fqdn}.target" ];
dovecotUnitSettings = {
wants = certificatesDeps;
after = certificatesDeps;
preStart =
let
directories = lib.strings.escapeShellArgs (
[ cfg.mailDirectory ] ++ lib.optional (cfg.indexDir != null) cfg.indexDir
);
in
''
# Create mail directory and set permissions. See
# <https://doc.dovecot.org/main/core/config/shared_mailboxes.html#filesystem-permissions-1>.
# Prevent world-readable paths, even temporarily.
umask 007
mkdir -p ${directories}
chgrp "${cfg.vmailGroupName}" ${directories}
chmod 02770 ${directories}
'';
};
in
{
config = lib.mkIf cfg.enable {
@ -60,25 +80,9 @@ in
};
# Create maildir folder before dovecot startup
systemd.services.dovecot2 = {
wants = certificatesDeps;
after = certificatesDeps;
preStart =
let
directories = lib.strings.escapeShellArgs (
[ cfg.mailDirectory ] ++ lib.optional (cfg.indexDir != null) cfg.indexDir
);
in
''
# Create mail directory and set permissions. See
# <https://doc.dovecot.org/main/core/config/shared_mailboxes.html#filesystem-permissions-1>.
# Prevent world-readable paths, even temporarily.
umask 007
mkdir -p ${directories}
chgrp "${cfg.vmailGroupName}" ${directories}
chmod 02770 ${directories}
'';
};
systemd.services.dovecot = dovecotUnitSettings;
# TODO: remove after 25.11 release
systemd.services.dovecot2 = dovecotUnitSettings;
# Postfix requires dovecot lmtp socket, dovecot auth socket and certificate to work
systemd.services.postfix = {