packaging: daily automated AUR rebuild for the [tanin] repo
A systemd user timer (daily) drives aur-autoupdate.sh, which rebuilds the AUR-only deps (eww-git, tiramisu-git, waypaper, calamares, …) in a clean devtools chroot and refreshes tanin.db. Non -git packages are skipped when their AUR version is unchanged (RPC check) so heavy ones like calamares aren't rebuilt for nothing; -git packages rebuild every run. Unattended: a sudoers drop-in grants passwordless access to the chroot helpers. Publishing is a TANIN_PUBLISH_CMD hook (no-op until hosting is wired) — the job refreshes the local repo dir for now. One-time: aur-autoupdate.sh setup (installs devtools, makes the chroot). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,7 @@
|
||||
# Passwordless chroot helpers so the daily AUR rebuild runs unattended.
|
||||
# Install: sudo install -m440 tanin-aur-update.sudoers /etc/sudoers.d/tanin-aur-update
|
||||
# Validate: sudo visudo -cf /etc/sudoers.d/tanin-aur-update
|
||||
#
|
||||
# Replace "karim" if the timer runs as a different user. These are exactly the
|
||||
# helpers devtools' makechrootpkg shells out to as root; nothing broader.
|
||||
karim ALL=(root) NOPASSWD: /usr/bin/makechrootpkg, /usr/bin/arch-nspawn, /usr/bin/mkarchroot
|
||||
Reference in New Issue
Block a user