Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions default/environment.d/10-omarchy-tmpdir.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
TMPDIR=${HOME}/.local/tmp
1 change: 1 addition & 0 deletions default/systemd/user-tmpfiles/omarchy-tmp.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
d %h/.local/tmp 0700 - - 10d
1 change: 1 addition & 0 deletions install/config/all.sh
Original file line number Diff line number Diff line change
Expand Up @@ -9,3 +9,4 @@ run_logged "$OMARCHY_INSTALL/config/docker.sh"
run_logged "$OMARCHY_INSTALL/config/snapper.sh"
run_logged "$OMARCHY_INSTALL/config/enable-services.sh"
run_logged "$OMARCHY_INSTALL/config/firewall.sh"
run_logged "$OMARCHY_INSTALL/config/user-tmpdir.sh"
32 changes: 32 additions & 0 deletions install/config/user-tmpdir.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
# setup to support private tmpdirs in ~
# ~/.local/tmp is created via /etc/skel in omarchy-settings
# * pam_env (ssh logins)
# * environment.d (systemd instantiated user env)
# * user-tmpfiles.d unit for cleanup

# ensure root has a local tmp

install -d -m 700 "/root/.local/tmp"

# Set user-tmpfiles cleanup for systemd

install -Dm644 /dev/stdin /usr/share/user-tmpfiles.d/omarchy-tmp.conf <<'EOF'
d %h/.local/tmp 0700 - - 10d
EOF

systemctl --global enable systemd-tmpfiles-setup.service systemd-tmpfiles-clean.timer

install -Dm644 \
"$OMARCHY_PATH/default/environment.d/10-omarchy-tmpdir.conf" \
/usr/lib/environment.d/10-omarchy-tmpdir.conf

# Same line install/config/user-tmpdir.sh writes on fresh installs; skip if
# TMPDIR is already managed there, by us or by the user.
grep -qE '^TMPDIR[[:space:]]' /etc/security/pam_env.conf && exit 0

tee -a /etc/security/pam_env.conf >/dev/null <<'EOF'

# Omarchy: use a private per-user tempdir where possible

TMPDIR DEFAULT=@{HOME}/.local/tmp
EOF
41 changes: 41 additions & 0 deletions migrations/1789168169.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@

echo "Set up private per-user temporary directories"
install -d -m 700 "$HOME/.local/tmp"


machine_marker="/var/lib/omarchy/migrations/1789168169"
[[ ! -e $machine_marker ]] || exit 0

echo "Set user TMPDIR via the PAM environment"

# Complementary with environment.d/10-omarchy-tmpdir.conf this sets TMPDIR
# in PAM controlled contexts such as ssh


# root also gets a local tmp.

sudo install -d -m 700 "/root/.local/tmp"

# Set user-tmpfiles cleanup for syste

sudo install -Dm644 /dev/stdin /usr/share/user-tmpfiles.d/omarchy-tmp.conf <<'EOF'
d %h/.local/tmp 0700 - - 10d
EOF

sudo systemctl --global enable systemd-tmpfiles-setup.service systemd-tmpfiles-clean.timer

sudo install -Dm644 /dev/stdin /usr/lib/environment.d/10-omarchy-tmpdir.conf <<'EOF'
TMPDIR=${HOME}/.local/tmp
EOF

if ! grep -qE '^TMPDIR[[:space:]]' /etc/security/pam_env.conf; then
sudo tee -a /etc/security/pam_env.conf >/dev/null <<'EOF'

# Omarchy: use a private per-user tempdir where possible

TMPDIR DEFAULT=@{HOME}/.local/tmp
EOF

fi

sudo install -Dm644 /dev/null "$machine_marker"