systemd: add sysupdated (#424101)

This commit is contained in:
Florian Klink
2025-07-17 02:04:13 +02:00
committed by GitHub
3 changed files with 28 additions and 6 deletions

View File

@@ -11,7 +11,14 @@ let
format = pkgs.formats.ini { listToValue = toString; };
definitionsDirectory = utils.systemdUtils.lib.definitions "sysupdate.d" format cfg.transfers;
# TODO: Switch back to using utils.systemdUtils.lib.definitions once
# https://github.com/systemd/systemd/pull/38187 is resolved. Also ensure
# utils.systemdUtils.lib.definitions is capable of setting a custom file
# suffix.
sysupdateTransfers = lib.mapAttrs' (name: value: {
name = "sysupdate.d/${name}.transfer";
value.source = format.generate "${name}.transfer" value;
}) cfg.transfers;
in
{
options.systemd.sysupdate = {
@@ -114,14 +121,23 @@ in
};
config = lib.mkIf cfg.enable {
assertions = [
{
assertion = config.systemd.package.withSysupdate;
message = "Cannot enable systemd-sysupdate with systemd package not built with sysupdate support";
}
];
systemd.additionalUpstreamSystemUnits = [
"systemd-sysupdate.service"
"systemd-sysupdate.timer"
"systemd-sysupdate-reboot.service"
"systemd-sysupdate-reboot.timer"
"systemd-sysupdated.service"
];
systemd.services.systemd-sysupdated.aliases = [ "dbus-org.freedesktop.sysupdate1.service" ];
systemd.timers = {
"systemd-sysupdate" = {
wantedBy = [ "timers.target" ];
@@ -133,8 +149,11 @@ in
};
};
environment.etc."sysupdate.d".source = definitionsDirectory;
environment.etc = sysupdateTransfers;
};
meta.maintainers = with lib.maintainers; [ nikstur ];
meta.maintainers = with lib.maintainers; [
nikstur
jmbaur
];
}

View File

@@ -1,7 +1,7 @@
# Tests downloading a signed update artifact from a server to a target machine.
# This test does not rely on the `systemd.timer` units provided by the
# `systemd-sysupdate` module but triggers the `systemd-sysupdate` service
# manually to make the test more robust.
# `systemd-sysupdate` module but triggers the `updatectl` tool directly to
# demonstrate how to initiate updates manually.
{ lib, pkgs, ... }:
@@ -62,7 +62,8 @@ in
testScript = ''
server.wait_for_unit("nginx.service")
target.succeed("systemctl start systemd-sysupdate")
print(target.succeed("updatectl list"))
target.succeed("updatectl update")
assert "nixos" in target.wait_until_succeeds("cat /nixos_1.txt", timeout=5)
'';
}

View File

@@ -559,6 +559,7 @@ stdenv.mkDerivation (finalAttrs: {
(lib.mesonEnable "libiptc" withIptables)
(lib.mesonEnable "repart" withRepart)
(lib.mesonEnable "sysupdate" withSysupdate)
(lib.mesonEnable "sysupdated" withSysupdate)
(lib.mesonEnable "seccomp" withLibseccomp)
(lib.mesonEnable "selinux" withSelinux)
(lib.mesonEnable "tpm2" withTpm2Tss)
@@ -905,6 +906,7 @@ stdenv.mkDerivation (finalAttrs: {
withMachined
withNetworkd
withPortabled
withSysupdate
withTimedated
withTpm2Tss
withUtmp