···187187 # fwupd-refresh expects a user that we do not create, so just run with DynamicUser
188188 # instead and ensure we take ownership of /var/lib/fwupd
189189 services.fwupd-refresh.serviceConfig = {
190190- DynamicUser = true;
191190 StateDirectory = "fwupd";
191191+ # Better for debugging, upstream sets stderr to null for some reason..
192192+ StandardError = "inherit";
192193 };
193194194195 timers.fwupd-refresh.wantedBy = [ "timers.target" ];
195196 };
197197+198198+ users.users.fwupd-refresh = {
199199+ isSystemUser = true;
200200+ group = "fwupd-refresh";
201201+ };
202202+ users.groups.fwupd-refresh = {};
196203197204 security.polkit.enable = true;
198205 };