Files
cachy-auto-update/res/systemd/cachy-auto-update.service
T
Felitendo ceb024d7be Add cachy-auto-update: unattended background updates for CachyOS
A root systemd service applies pacman, AUR, Flatpak and AppImage updates on
its own, gated on battery state, gaming activity and whether anybody else is
using the package system. The CLI is deliberately two switches plus status.

No user password is stored anywhere: pacman runs as root directly, and the AUR
step - which makepkg forbids running as root - drops to a locked system account
that sudoers permits to call pacman without a password.
2026-08-08 02:27:04 +02:00

38 lines
1.3 KiB
Desktop File

[Unit]
Description=CachyOS unattended update run
Documentation=man:cachy-auto-update(1)
Documentation=https://github.com/Felitendo/cachy-auto-update
After=network-online.target
Wants=network-online.target
ConditionPathExists=/etc/cachy-auto-update/cachy-auto-update.conf
[Service]
Type=oneshot
ExecStart=/usr/lib/cachy-auto-update/cachy-auto-update-run
# Tool output has to stay parseable; everything shown to a human is rendered
# back into their own locale explicitly.
Environment=LC_ALL=C
# Stay out of the way of whatever the user is actually doing. Building an AUR
# package should never make the desktop stutter.
Nice=19
CPUSchedulingPolicy=idle
IOSchedulingClass=idle
IOSchedulingPriority=7
OOMScoreAdjust=500
# A large AUR package can legitimately take a long time to build.
TimeoutStartSec=4h
# Deliberately *not* sandboxed the way paccache.service is: this unit installs
# packages across the whole filesystem and downloads them over the network, so
# ProtectSystem=, PrivateNetwork= and friends would break it. NoNewPrivileges
# in particular has to stay off - the AUR step relies on the build account
# calling sudo.
NoNewPrivileges=no
ProtectHostname=yes
# No [Install] section on purpose: this is driven by cachy-auto-update.timer,
# never wanted by a target of its own.