From f7080c060690365e55364dc5320099bed67f69c8 Mon Sep 17 00:00:00 2001 From: Jared Baur Date: Thu, 10 Jul 2025 09:48:59 -0700 Subject: [PATCH 1/6] systemd: add sysupdated --- pkgs/os-specific/linux/systemd/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/os-specific/linux/systemd/default.nix b/pkgs/os-specific/linux/systemd/default.nix index 80a9ae1bb550..f30db465560a 100644 --- a/pkgs/os-specific/linux/systemd/default.nix +++ b/pkgs/os-specific/linux/systemd/default.nix @@ -559,6 +559,7 @@ stdenv.mkDerivation (finalAttrs: { (lib.mesonEnable "libiptc" withIptables) (lib.mesonEnable "repart" withRepart) (lib.mesonEnable "sysupdate" withSysupdate) + (lib.mesonEnable "sysupdated" withSysupdate) (lib.mesonEnable "seccomp" withLibseccomp) (lib.mesonEnable "selinux" withSelinux) (lib.mesonEnable "tpm2" withTpm2Tss) From cbb2734d993b3acc9f21792f06b4b8393e96ebbb Mon Sep 17 00:00:00 2001 From: Jared Baur Date: Thu, 10 Jul 2025 21:55:14 -0700 Subject: [PATCH 2/6] systemd: add withSysupdate to passthru --- pkgs/os-specific/linux/systemd/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/os-specific/linux/systemd/default.nix b/pkgs/os-specific/linux/systemd/default.nix index f30db465560a..d6af487a9692 100644 --- a/pkgs/os-specific/linux/systemd/default.nix +++ b/pkgs/os-specific/linux/systemd/default.nix @@ -906,6 +906,7 @@ stdenv.mkDerivation (finalAttrs: { withMachined withNetworkd withPortabled + withSysupdate withTimedated withTpm2Tss withUtmp From 45a71d67a70c448be7dc86c6a7d7dbacfeae8f56 Mon Sep 17 00:00:00 2001 From: Jared Baur Date: Thu, 10 Jul 2025 21:57:37 -0700 Subject: [PATCH 3/6] nixos/sysupdate: add assertion for systemd built with sysupdate support --- nixos/modules/system/boot/systemd/sysupdate.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/nixos/modules/system/boot/systemd/sysupdate.nix b/nixos/modules/system/boot/systemd/sysupdate.nix index 4c71b1714954..354cd0027c91 100644 --- a/nixos/modules/system/boot/systemd/sysupdate.nix +++ b/nixos/modules/system/boot/systemd/sysupdate.nix @@ -114,6 +114,12 @@ in }; config = lib.mkIf cfg.enable { + assertions = [ + { + assertion = config.systemd.package.withSysupdate; + message = "Cannot enable systemd-sysupdate with systemd package not built with sysupdate support"; + } + ]; systemd.additionalUpstreamSystemUnits = [ "systemd-sysupdate.service" From 7b981efa880d3e78beb56df4caaf2240ffee7461 Mon Sep 17 00:00:00 2001 From: Jared Baur Date: Fri, 11 Jul 2025 23:44:38 -0700 Subject: [PATCH 4/6] nixos/sysupdate: add support for sysupdated/updatectl --- nixos/modules/system/boot/systemd/sysupdate.nix | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/nixos/modules/system/boot/systemd/sysupdate.nix b/nixos/modules/system/boot/systemd/sysupdate.nix index 354cd0027c91..1aba22235c12 100644 --- a/nixos/modules/system/boot/systemd/sysupdate.nix +++ b/nixos/modules/system/boot/systemd/sysupdate.nix @@ -11,7 +11,14 @@ let format = pkgs.formats.ini { listToValue = toString; }; - definitionsDirectory = utils.systemdUtils.lib.definitions "sysupdate.d" format cfg.transfers; + # TODO: Switch back to using utils.systemdUtils.lib.definitions once + # https://github.com/systemd/systemd/pull/38187 is resolved. Also ensure + # utils.systemdUtils.lib.definitions is capable of setting a custom file + # suffix. + sysupdateTransfers = lib.mapAttrs' (name: value: { + name = "sysupdate.d/${name}.transfer"; + value.source = format.generate "${name}.transfer" value; + }) cfg.transfers; in { options.systemd.sysupdate = { @@ -126,8 +133,11 @@ in "systemd-sysupdate.timer" "systemd-sysupdate-reboot.service" "systemd-sysupdate-reboot.timer" + "systemd-sysupdated.service" ]; + systemd.services.systemd-sysupdated.aliases = [ "dbus-org.freedesktop.sysupdate1.service" ]; + systemd.timers = { "systemd-sysupdate" = { wantedBy = [ "timers.target" ]; @@ -139,7 +149,7 @@ in }; }; - environment.etc."sysupdate.d".source = definitionsDirectory; + environment.etc = sysupdateTransfers; }; meta.maintainers = with lib.maintainers; [ nikstur ]; From 996cc69171d427cf02fe8768ca36454586fd29a8 Mon Sep 17 00:00:00 2001 From: Jared Baur Date: Fri, 11 Jul 2025 23:45:05 -0700 Subject: [PATCH 5/6] nixos/sysupdate: add jmbaur as maintainer --- nixos/modules/system/boot/systemd/sysupdate.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/nixos/modules/system/boot/systemd/sysupdate.nix b/nixos/modules/system/boot/systemd/sysupdate.nix index 1aba22235c12..0f8bc2dd966b 100644 --- a/nixos/modules/system/boot/systemd/sysupdate.nix +++ b/nixos/modules/system/boot/systemd/sysupdate.nix @@ -152,5 +152,8 @@ in environment.etc = sysupdateTransfers; }; - meta.maintainers = with lib.maintainers; [ nikstur ]; + meta.maintainers = with lib.maintainers; [ + nikstur + jmbaur + ]; } From 61d37d773358ee34d5fffd99e38eb566981effbd Mon Sep 17 00:00:00 2001 From: Jared Baur Date: Fri, 11 Jul 2025 23:45:16 -0700 Subject: [PATCH 6/6] nixosTests.systemd-sysupdate: use updatectl as frontend for updates --- nixos/tests/systemd-sysupdate.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/nixos/tests/systemd-sysupdate.nix b/nixos/tests/systemd-sysupdate.nix index 059f2db5df41..5ab5da738171 100644 --- a/nixos/tests/systemd-sysupdate.nix +++ b/nixos/tests/systemd-sysupdate.nix @@ -1,7 +1,7 @@ # Tests downloading a signed update artifact from a server to a target machine. # This test does not rely on the `systemd.timer` units provided by the -# `systemd-sysupdate` module but triggers the `systemd-sysupdate` service -# manually to make the test more robust. +# `systemd-sysupdate` module but triggers the `updatectl` tool directly to +# demonstrate how to initiate updates manually. { lib, pkgs, ... }: @@ -62,7 +62,8 @@ in testScript = '' server.wait_for_unit("nginx.service") - target.succeed("systemctl start systemd-sysupdate") + print(target.succeed("updatectl list")) + target.succeed("updatectl update") assert "nixos" in target.wait_until_succeeds("cat /nixos_1.txt", timeout=5) ''; }