AdguardTeam / AdguardTeam/AdGuardHome

Add option to enable auto-upgrade on Linux/Unix despite CAP_NET_BIND_SERVICE capability

Offen
#1,944 5 Kommentare 2 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
feature request help wanted
Vorherrschende Sprache
TypeScript
Sterne
36.9k
Forks
2.5k
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

### Problem Description

The if statement linked below rightly describes the issue with setting `CAP_NET_BIND_SERVICE` on binary _files_ in Linux but doesn't account for setting this option using _systemd's_ `AmbientCapabilities` directive instead, which doesn't require setting the capability on the binary itself.

https://github.com/AdguardTeam/AdGuardHome/blob/b4aa79151315035f0e839d9a710fe4051595acb5/home/control_update.go#L101-L111

### Proposed Solution

Modify the if statement logic to allow users to override the behavior, perhaps with a command line flag like `--allow-auto-update`? When combined with the AmbientCapabilities systemd directive, this would allow users to auto upgrade the binary even when running AdGuardHome without root permissions.

**Systemd Service File Example**
```ini
AmbientCapabilities=CAP_NET_BIND_SERVICE
```

### Alternatives Considered

Script the upgrade myself or fork the code, but a native solution would be much easier and a benefit for other Linux users. Thanks for the great application!

### Additional Information

- [func getVersionResp][1]
- [systemd.exec AmbientCapabilities][2]

[1]: https://github.com/AdguardTeam/AdGuardHome/blob/b4aa79151315035f0e839d9a710fe4051595acb5/home/control_update.go#L87-L117
[2]: https://www.freedesktop.org/software/systemd/man/systemd.exec.html#AmbientCapabilities=

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.