···187187 # fwupd-refresh expects a user that we do not create, so just run with DynamicUser
188188 # instead and ensure we take ownership of /var/lib/fwupd
189189 services.fwupd-refresh.serviceConfig = {
190190- DynamicUser = true;
191190 StateDirectory = "fwupd";
192191 };
193192194193 timers.fwupd-refresh.wantedBy = [ "timers.target" ];
195194 };
195195+196196+ users.users.fwupd-refresh = {
197197+ isSystemUser = true;
198198+ group = "fwupd-refresh";
199199+ };
200200+ users.groups.fwupd-refresh = {};
196201197202 security.polkit.enable = true;
198203 };