Configure warnquota Notifications Without Surprises
You will configure warnquota 4.06 to send a useful warning when a local filesystem user reaches a quota soft limit, then verify the configuration without deliberately sending a message to every affected user. The same workflow covers group warnings and the small configuration files that make quota mail understandable.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about 20 minutes if quota accounting and a local mail transport are already working. You need root access, enabled quotas on the filesystem you will check, and a working local mail command. The examples use /srv/home as a placeholder. Replace it with a real quota-enabled mountpoint before running anything.
Checkpoint: confirm the installed tool
Check the version and available options as an ordinary user.
warnquota --version warnquota --help
On the system used for this guide, the result identifies Quota utilities version 4.06, packaged as quota 4.06-1build6. The local binary also accepts -I or --ignore-config-errors, which is shown by its help output but is not described in the installed warnquota(8) reference. Do not use that option as a substitute for fixing a configuration error.
Checkpoint: make user notifications readable
Create a temporary configuration containing the sender, support contact and message text. This step changes a file only under
/tmp.cat > /tmp/warnquota.conf.example <<'EOF' FROM = [email protected] SUPPORT = [email protected] PHONE = +44 20 0000 0000 SUBJECT = Disk quota warning on %h MESSAGE = Hello %i,|your disk quota on %h has been exceeded.|Please remove files or contact %s. SIGNATURE = Storage support: %s|%d EOFInspect the file before using it as root.
sed -n '1,20p' /tmp/warnquota.conf.example
Configuration syntax is an option name, an equals sign and a value. Blank lines and lines beginning with # or ; are ignored. Values may be quoted and may continue onto another line when the previous line ends with a backslash.
The format sequences in this example are meaningful: %h is the host name, %i is the user or group name, %s is the support value, %d is the domain, and | inserts a newline. In SUBJECT, the host name gives an operator enough context to recognise which machine generated the message. A literal percent sign is written as %%.
For a real deployment, install the reviewed file as /etc/warnquota.conf. This is an elevated, persistent change. Preserve the old file so that undo is straightforward.
sudo cp -p /etc/warnquota.conf /etc/warnquota.conf.before-warnquota 2>/dev/null || true
sudo install -o root -g root -m 0644 /tmp/warnquota.conf.example /etc/warnquota.conf
Recovery is simply restoring the saved file when it exists, then rerunning the verification command:
sudo test -f /etc/warnquota.conf.before-warnquota && \
sudo cp -p /etc/warnquota.conf.before-warnquota /etc/warnquota.conf
Checkpoint: describe the filesystem in quota mail
Write a device description in a temporary quota table.
cat > /tmp/quotatab.example <<'EOF' /dev/mapper/vg0-home: Home directories.|Quota warnings for this filesystem. EOF sed -n '1,5p' /tmp/quotatab.exampleInstall the reviewed table as root if the device path matches the mounted filesystem.
findmnt -no SOURCE,TARGET /srv/home sudo cp -p /etc/quotatab /etc/quotatab.before-warnquota 2>/dev/null || true sudo install -o root -g root -m 0644 /tmp/quotatab.example /etc/quotatab
Each quotatab line has a device path, a colon and a description. Surrounding whitespace, apostrophes and double quotes are stripped. A pipe in the description becomes a newline in the notification. The path must identify the device, not merely the directory you happen to use as a mountpoint, so check it with findmnt first.
Checkpoint: run a narrow, non-mail test
Run the command against one filesystem with the reviewed files, human-readable values and no attached quota report.
sudo warnquota --user --human-readable --no-details \ --config=/etc/warnquota.conf \ --quota-tab=/etc/quotatab \ /srv/home
This checks the selected local filesystem and does not attach the quota report to the message. It can still send mail to users that meet the warning condition. The command normally prints nothing on success, so verify its exit status immediately if you are scripting it:
sudo warnquota --user --no-details /srv/home
status=$?
printf 'warnquota exit status: %s\n' "$status"
test "$status" -eq 0
Do not omit the filesystem argument during a first run. With no filesystem named, warnquota checks each local filesystem, which can create a burst of mail and makes a bad device description harder to isolate. It normally uses local filesystems from /etc/mtab.
Group warnings and their separate recipient file
Group mode is a different recipient workflow. It checks group quotas, then sends a warning to the user named for the group in /etc/quotagrpadmins. It does not infer a group administrator from the group database.
Review a group administrator mapping in a temporary file.
cat > /tmp/quotagrpadmins.example <<'EOF' projects: [email protected] EOFInstall it only after checking the address and group name.
getent group projects sudo cp -p /etc/quotagrpadmins /etc/quotagrpadmins.before-warnquota 2>/dev/null || true sudo install -o root -g root -m 0644 /tmp/quotagrpadmins.example /etc/quotagrpadminsRun group mode against the same single filesystem.
sudo warnquota --group --human-readable \ --admins-file=/etc/quotagrpadmins \ /srv/home
Whitespace around the group and recipient is allowed. Empty lines and lines beginning with # or ; are ignored. Restore /etc/quotagrpadmins.before-warnquota if this test used the wrong recipient.
Common traps and safe operating choices
Full mail storage: set
MAILDEVto the device holding mailboxes, or toanywhen appropriate, so warnings do not bounce because the destination filesystem is full.Unexpected sender:
MAIL_CMDdefaults to/usr/lib/sendmail -t. The command receives the complete message, including headers, on standard input. Change it only after testing the replacement mail transport.Autofs noise: use
--no-autofswhen automounted filesystems should not be checked.Quota format: quota format autodetection is the default. Use
--format=vfsv0,vfsv1,vfsoldorxfsonly when you have verified the filesystem's format.LDAP mail lookup: it is disabled by default. If you enable
LDAP_MAIL, treat the bind password and directory endpoint as security-sensitive configuration and restrict the file permissions.
Done means
warnquota --versionreports the installed version you tested./etc/warnquota.confhas a reviewed sender, recipient behaviour and message./etc/quotatabdescribes the actual quota device.- User mode has been run against one named filesystem and returned status 0.
- Group mode is used only when
/etc/quotagrpadminsmaps each group to an intentional recipient. - Any saved
.before-warnquotafile can restore the previous configuration.