From 768715d0769b824429c57d1c744f5c8bf7561367 Mon Sep 17 00:00:00 2001 From: Tommy Date: Fri, 6 Jun 2025 02:19:12 -0700 Subject: [PATCH] Cleanup & enable podman-auto-update Signed-off-by: Tommy --- x86.yml | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/x86.yml b/x86.yml index 8fa59d6..da900ee 100644 --- a/x86.yml +++ b/x86.yml @@ -35,10 +35,7 @@ systemd: # `ConditionFirstBoot=true` services won't rerun on the next boot. After=systemd-machine-id-commit.service After=network-online.target - # We run before `zincati.service` to avoid conflicting rpm-ostree - # transactions. Before=zincati.service - ConditionPathExists=!/var/lib/%N.stamp [Service] Type=oneshot @@ -49,9 +46,8 @@ systemd: ExecStart=/usr/sbin/setsebool -P virt_use_samba off ExecStart=/usr/bin/rpm-ostree install hardened_malloc qemu-guest-agent tuned ExecStart=/usr/bin/sed -i 's/\s+nullok//g' /etc/pam.d/system-auth - ExecStart=/usr/bin/systemctl disable systemd-resolved - ExecStart=/usr/bin/rm /etc/resolv.conf - ExecStart=/usr/bin/touch /var/lib/%N.stamp + ExecStart=/usr/bin/systemctl disable postinst + ExecStart=/usr/bin/rm /etc/systemd/system/postinst.service ExecStart=/usr/bin/echo 'libhardened_malloc.so' > /etc/ld.so.preload ExecStart=/usr/bin/systemctl --no-block reboot @@ -63,6 +59,8 @@ systemd: mask: true - name: docker.service enabled: false + - name: podman-auto-update.timer + enabled: true - name: rpm-ostree-countme.timer enabled: false mask: true