A root systemd service applies pacman, AUR, Flatpak and AppImage updates on its own, gated on battery state, gaming activity and whether anybody else is using the package system. The CLI is deliberately two switches plus status. No user password is stored anywhere: pacman runs as root directly, and the AUR step - which makepkg forbids running as root - drops to a locked system account that sudoers permits to call pacman without a password.
7 lines
362 B
Plaintext
7 lines
362 B
Plaintext
# The account that builds and installs AUR packages.
|
|
#
|
|
# makepkg, paru and yay all refuse to run as root, so the update service drops
|
|
# to this account for the AUR step. It has no password and no shell: nobody can
|
|
# log into it, and only root can become it.
|
|
u cachy-auto-update - "CachyOS Auto-Update builder" /var/lib/cachy-auto-update/builder /usr/bin/nologin
|