From 106e5bac52f91647c13d0ab28964dbdcf204a128 Mon Sep 17 00:00:00 2001 From: Moss Date: Fri, 11 Sep 2026 19:05:09 -0700 Subject: [PATCH] set private per-user tmpdir --- default/environment.d/10-omarchy-tmpdir.conf | 1 + .../systemd/user-tmpfiles/omarchy-tmp.conf | 1 + install/config/all.sh | 1 + install/config/user-tmpdir.sh | 32 +++++++++++++++ migrations/1789168169.sh | 41 +++++++++++++++++++ 5 files changed, 76 insertions(+) create mode 100644 default/environment.d/10-omarchy-tmpdir.conf create mode 100644 default/systemd/user-tmpfiles/omarchy-tmp.conf create mode 100644 install/config/user-tmpdir.sh create mode 100644 migrations/1789168169.sh diff --git a/default/environment.d/10-omarchy-tmpdir.conf b/default/environment.d/10-omarchy-tmpdir.conf new file mode 100644 index 00000000000..175b01526fc --- /dev/null +++ b/default/environment.d/10-omarchy-tmpdir.conf @@ -0,0 +1 @@ +TMPDIR=${HOME}/.local/tmp diff --git a/default/systemd/user-tmpfiles/omarchy-tmp.conf b/default/systemd/user-tmpfiles/omarchy-tmp.conf new file mode 100644 index 00000000000..efcc7e13662 --- /dev/null +++ b/default/systemd/user-tmpfiles/omarchy-tmp.conf @@ -0,0 +1 @@ +d %h/.local/tmp 0700 - - 10d diff --git a/install/config/all.sh b/install/config/all.sh index a221a39896d..fc75b095e03 100644 --- a/install/config/all.sh +++ b/install/config/all.sh @@ -9,3 +9,4 @@ run_logged "$OMARCHY_INSTALL/config/docker.sh" run_logged "$OMARCHY_INSTALL/config/snapper.sh" run_logged "$OMARCHY_INSTALL/config/enable-services.sh" run_logged "$OMARCHY_INSTALL/config/firewall.sh" +run_logged "$OMARCHY_INSTALL/config/user-tmpdir.sh" diff --git a/install/config/user-tmpdir.sh b/install/config/user-tmpdir.sh new file mode 100644 index 00000000000..3d5824b666f --- /dev/null +++ b/install/config/user-tmpdir.sh @@ -0,0 +1,32 @@ +# setup to support private tmpdirs in ~ +# ~/.local/tmp is created via /etc/skel in omarchy-settings +# * pam_env (ssh logins) +# * environment.d (systemd instantiated user env) +# * user-tmpfiles.d unit for cleanup + +# ensure root has a local tmp + +install -d -m 700 "/root/.local/tmp" + +# Set user-tmpfiles cleanup for systemd + +install -Dm644 /dev/stdin /usr/share/user-tmpfiles.d/omarchy-tmp.conf <<'EOF' +d %h/.local/tmp 0700 - - 10d +EOF + +systemctl --global enable systemd-tmpfiles-setup.service systemd-tmpfiles-clean.timer + +install -Dm644 \ + "$OMARCHY_PATH/default/environment.d/10-omarchy-tmpdir.conf" \ + /usr/lib/environment.d/10-omarchy-tmpdir.conf + +# Same line install/config/user-tmpdir.sh writes on fresh installs; skip if +# TMPDIR is already managed there, by us or by the user. +grep -qE '^TMPDIR[[:space:]]' /etc/security/pam_env.conf && exit 0 + +tee -a /etc/security/pam_env.conf >/dev/null <<'EOF' + +# Omarchy: use a private per-user tempdir where possible + +TMPDIR DEFAULT=@{HOME}/.local/tmp +EOF diff --git a/migrations/1789168169.sh b/migrations/1789168169.sh new file mode 100644 index 00000000000..bc21e00c9d6 --- /dev/null +++ b/migrations/1789168169.sh @@ -0,0 +1,41 @@ + +echo "Set up private per-user temporary directories" +install -d -m 700 "$HOME/.local/tmp" + + +machine_marker="/var/lib/omarchy/migrations/1789168169" +[[ ! -e $machine_marker ]] || exit 0 + +echo "Set user TMPDIR via the PAM environment" + +# Complementary with environment.d/10-omarchy-tmpdir.conf this sets TMPDIR +# in PAM controlled contexts such as ssh + + +# root also gets a local tmp. + +sudo install -d -m 700 "/root/.local/tmp" + +# Set user-tmpfiles cleanup for syste + +sudo install -Dm644 /dev/stdin /usr/share/user-tmpfiles.d/omarchy-tmp.conf <<'EOF' +d %h/.local/tmp 0700 - - 10d +EOF + +sudo systemctl --global enable systemd-tmpfiles-setup.service systemd-tmpfiles-clean.timer + +sudo install -Dm644 /dev/stdin /usr/lib/environment.d/10-omarchy-tmpdir.conf <<'EOF' +TMPDIR=${HOME}/.local/tmp +EOF + +if ! grep -qE '^TMPDIR[[:space:]]' /etc/security/pam_env.conf; then + sudo tee -a /etc/security/pam_env.conf >/dev/null <<'EOF' + +# Omarchy: use a private per-user tempdir where possible + +TMPDIR DEFAULT=@{HOME}/.local/tmp +EOF + +fi + +sudo install -Dm644 /dev/null "$machine_marker"