Move service runtime state out of /usr/share/aqomui #174

Open
opened 2026-08-27 13:20:31 -04:00 by mysticalsoap · 0 comments
Owner

The FHS reserves /usr/share for static, package-owned data, but the service writes all of its runtime state into it. A live install's directory listing is a timeline of the violation: the files stamped with the package build date are pacman's, everything else is the service's — config.json, firewall.json, homedirs.json, per-provider import dirs (openvpn.conf plus certs, session and auth files), per-connection temp.ovpn / hop.ovpn / bypass.ovpn / temp.ssl / wg confs, iptables_before.rules / ip6tables_before.rules, and logs/.

Costs: breaks on read-only /usr; pacman -Qkk reports the package modified; uninstall leaves unowned state behind; shipped assets and mutable state are indistinguishable in one flat directory.

Split, mapping onto systemd's directory directives:

  • /var/lib/aqomui (StateDirectory=) — config.json, firewall.json, homedirs.json, provider import dirs (auth files keep their 600)
  • /run/aqomui (RuntimeDirectory=) — per-connection generated configs and the firewall snapshot rules; all meaningless across a reboot
  • /var/log/aqomui (LogsDirectory=) — logs/, or drop the file handler for journald
  • /usr/share/aqomui keeps only what the PKGBUILD installs: countries.json, flags/, provider *_config templates, the AirVPN pems, ssl_config, VERSION, scripts

Mechanics: #173 centralized the path constants in config.py, so this is adding STATEDIR/RUNDIR beside ROOTDIR and reclassifying each site, plus a one-time migration on service start for existing installs. The firewall save/restore path needs live verification.

Tangles: #175 (user-side XDG move) — homedirs.json embeds the per-user directory convention, so the service must learn the new user path when that lands. Orthogonal to the #83 service/ package move but touches the same files; whichever lands second rebases mechanically.

The FHS reserves /usr/share for static, package-owned data, but the service writes all of its runtime state into it. A live install's directory listing is a timeline of the violation: the files stamped with the package build date are pacman's, everything else is the service's — config.json, firewall.json, homedirs.json, per-provider import dirs (openvpn.conf plus certs, session and auth files), per-connection temp.ovpn / hop.ovpn / bypass.ovpn / temp.ssl / wg confs, iptables_before.rules / ip6tables_before.rules, and logs/. Costs: breaks on read-only /usr; `pacman -Qkk` reports the package modified; uninstall leaves unowned state behind; shipped assets and mutable state are indistinguishable in one flat directory. Split, mapping onto systemd's directory directives: - `/var/lib/aqomui` (`StateDirectory=`) — config.json, firewall.json, homedirs.json, provider import dirs (auth files keep their 600) - `/run/aqomui` (`RuntimeDirectory=`) — per-connection generated configs and the firewall snapshot rules; all meaningless across a reboot - `/var/log/aqomui` (`LogsDirectory=`) — logs/, or drop the file handler for journald - `/usr/share/aqomui` keeps only what the PKGBUILD installs: countries.json, flags/, provider *_config templates, the AirVPN pems, ssl_config, VERSION, scripts Mechanics: #173 centralized the path constants in config.py, so this is adding STATEDIR/RUNDIR beside ROOTDIR and reclassifying each site, plus a one-time migration on service start for existing installs. The firewall save/restore path needs live verification. Tangles: #175 (user-side XDG move) — homedirs.json embeds the per-user directory convention, so the service must learn the new user path when that lands. Orthogonal to the #83 service/ package move but touches the same files; whichever lands second rebases mechanically.
Sign in to join this conversation.
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
mysticalsoap/aqomui#174
No description provided.