TallyNote release / linux-x64 (push) Failing after 3m12s
- Download happens in web process (non-root) with real-time progress - Root runner only handles privileged apply (stop/backup/switch/restart) - Eliminates 'waiting for system scheduler' stuck state - Frontend shows download bytes/speed/percentage with cancel button - Staged download triggers apply request file for root runner - systemd timeout reduced from 32min to 5min (no download phase) - Tests adapted for synchronous download flow release: 1.3.0
35 lines
1.2 KiB
Desktop File
35 lines
1.2 KiB
Desktop File
[Unit]
|
|
Description=TallyNote privileged release updater
|
|
[Service]
|
|
Type=oneshot
|
|
User=root
|
|
Group=root
|
|
WorkingDirectory=/opt/tallynote/current
|
|
EnvironmentFile=-/etc/tallynote/tallynote.env
|
|
ExecStart=/usr/local/libexec/tallynote-update-runner
|
|
Environment=PATH=/usr/sbin:/usr/bin:/sbin:/bin
|
|
# The runner consumes queued requests immediately and applies its own bounded
|
|
# phase timeouts while keeping full CLI diagnostics in the runner log.
|
|
# Archive validation and data backups can exceed systemd's 90s
|
|
# default start timeout on a slower server. Keep one update job alive long
|
|
# enough to finish or reach its own health-check/recovery path.
|
|
TimeoutStartSec=5min
|
|
NoNewPrivileges=true
|
|
# Keep the updater compatible with the same Node/libuv interface discovery
|
|
# path while retaining an explicit socket-family allowlist.
|
|
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
|
|
PrivateTmp=true
|
|
PrivateDevices=true
|
|
ProtectHome=true
|
|
ProtectSystem=strict
|
|
ProtectKernelTunables=true
|
|
ProtectKernelModules=true
|
|
ProtectKernelLogs=true
|
|
ProtectClock=true
|
|
LockPersonality=true
|
|
RestrictRealtime=true
|
|
RestrictSUIDSGID=true
|
|
SystemCallArchitectures=native
|
|
UMask=0077
|
|
ReadWritePaths=/opt/tallynote /var/lib/tallynote /var/lib/tallynote-backups
|