Add cachy-auto-update: unattended background updates for CachyOS
A root systemd service applies pacman, AUR, Flatpak and AppImage updates on its own, gated on battery state, gaming activity and whether anybody else is using the package system. The CLI is deliberately two switches plus status. No user password is stored anywhere: pacman runs as root directly, and the AUR step - which makepkg forbids running as root - drops to a locked system account that sudoers permits to call pacman without a password.
This commit is contained in:
1 parent
327da1dae3
commit
ceb024d7be
28 files changed
+3856
-1
No files matched your search
@@ -0,0 +1,19 @@
|
||||
# Privilege bridge for unattended AUR updates.
|
||||
#
|
||||
# makepkg, paru and yay refuse to run as root, so the update service runs them
|
||||
# as the "cachy-auto-update" system account. That account then needs to be able
|
||||
# to hand the finished packages to pacman without a human typing a password.
|
||||
#
|
||||
# The account is created by sysusers.d with no password and /usr/bin/nologin:
|
||||
# it cannot be logged into, and only root can become it. Since the service that
|
||||
# uses it already runs as root, this rule does not widen the trust boundary -
|
||||
# it only lets an existing root process take the detour that makepkg demands.
|
||||
#
|
||||
# The rule is deliberately not restricted by arguments. paru and yay call
|
||||
# pacman with argument lists that vary per transaction, so any pattern match
|
||||
# would give the appearance of a restriction while breaking at random.
|
||||
|
||||
Defaults:cachy-auto-update !requiretty
|
||||
Defaults:cachy-auto-update env_keep += "PACMAN"
|
||||
|
||||
cachy-auto-update ALL=(root) NOPASSWD: /usr/bin/pacman
|
||||
Reference in new issue
Block a user