AdguardTeam / AdguardTeam/AdGuardHome
Add option to enable auto-upgrade on Linux/Unix despite CAP_NET_BIND_SERVICE capability
- Vorherrschende Sprache
- TypeScript
- Sterne
- 36.9k
- Forks
- 2.5k
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
### Problem Description
The if statement linked below rightly describes the issue with setting `CAP_NET_BIND_SERVICE` on binary _files_ in Linux but doesn't account for setting this option using _systemd's_ `AmbientCapabilities` directive instead, which doesn't require setting the capability on the binary itself.
https://github.com/AdguardTeam/AdGuardHome/blob/b4aa79151315035f0e839d9a710fe4051595acb5/home/control_update.go#L101-L111
### Proposed Solution
Modify the if statement logic to allow users to override the behavior, perhaps with a command line flag like `--allow-auto-update`? When combined with the AmbientCapabilities systemd directive, this would allow users to auto upgrade the binary even when running AdGuardHome without root permissions.
**Systemd Service File Example**
```ini
AmbientCapabilities=CAP_NET_BIND_SERVICE
```
### Alternatives Considered
Script the upgrade myself or fork the code, but a native solution would be much easier and a benefit for other Linux users. Thanks for the great application!
### Additional Information
- [func getVersionResp][1]
- [systemd.exec AmbientCapabilities][2]
[1]: https://github.com/AdguardTeam/AdGuardHome/blob/b4aa79151315035f0e839d9a710fe4051595acb5/home/control_update.go#L87-L117
[2]: https://www.freedesktop.org/software/systemd/man/systemd.exec.html#AmbientCapabilities=
Beitragsleitfaden
Bewertung
Dieses Issue wurde noch nicht bewertet.