Say when the systemd unit has moved on
update.sh pulls the code and restarts, and says nothing about the unit -- so a host can run a new release under the old confinement and fail in a way that points nowhere. Dropping ProtectKernelTunables is exactly such a change: without it applied, an agent chat cannot start a sandbox at all. It compares the *template* against the one last applied here rather than against the installed file. An installed unit grows host-specific lines -- an ordering dependency on whatever serves the models, a note about how the prefix is mounted -- and diffing the files would warn about those forever. A warning that always fires is one nobody reads. Reinstalling automatically would clobber those same lines, so it only says so and leaves the merge to a person. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -110,6 +110,10 @@ sudo install -d -o "$SERVICE_USER" -g "$SERVICE_USER" -m 750 "$PREFIX/data"
|
||||
echo "== systemd unit =="
|
||||
sed -e "s|__PREFIX__|$PREFIX|g" -e "s|__SERVICE_USER__|$SERVICE_USER|g" \
|
||||
"$HERE/lembas.service" | sudo tee /etc/systemd/system/lembas.service >/dev/null
|
||||
# Which version of the template this host is running. update.sh compares
|
||||
# against it and says so when the template moves on, because the installed
|
||||
# unit usually grows host-specific lines and cannot simply be overwritten.
|
||||
sha256sum "$HERE/lembas.service" | cut -d' ' -f1 | sudo tee "$PREFIX/.unit-applied" >/dev/null
|
||||
sudo systemctl daemon-reload
|
||||
|
||||
echo "== self-signed cert for $SITE_HOST =="
|
||||
|
||||
Reference in New Issue
Block a user