@@ -1,6 +1,7 @@
;;; GNU Guix --- Functional package management for GNU
;;; Copyright © 2017, 2018, 2019, 2020, 2022 Ludovic Courtès <ludo@gnu.org>
;;; Copyright © 2020 Mathieu Othacehe <othacehe@gnu.org>
+;;; Copyright © 2022 Leo Nikkilä <hello@lnikki.la>
;;;
;;; This file is part of GNU Guix.
;;;
@@ -119,8 +120,9 @@ (define* (read-pid-file/container pid pid-file #:key (max-delay 5))
;; PID is always 1, but that's not what Shepherd needs to know.
pid)))
-(define* (exec-command* command #:key user group log-file pid-file
- directory (environment-variables (environ)))
+(define* (exec-command* command #:key user group (supplementary-groups '())
+ log-file pid-file directory (environment-variables
+ (environ)))
"Like 'exec-command', but first restore signal handles modified by
shepherd (PID 1)."
;; First restore the default handlers.
@@ -135,6 +137,7 @@ (define* (exec-command* command #:key user group log-file pid-file
(exec-command command
#:user user
#:group group
+ #:supplementary-groups supplementary-groups
#:log-file log-file
#:directory directory
#:environment-variables environment-variables))
@@ -146,6 +149,7 @@ (define* (make-forkexec-constructor/container command
(mappings '())
(user #f)
(group #f)
+ (supplementary-groups '())
(log-file #f)
pid-file
(pid-file-timeout 5)
@@ -192,6 +196,8 @@ (define mounts
(exec-command* command
#:user user
#:group group
+ #:supplementary-groups
+ supplementary-groups
#:pid-file pid-file
#:log-file log-file
#:directory directory