DocumentationДокументация

Use the binary you built, not a surprise download.Ставьте бинарник, который собрали сами, а не случайную загрузку.

SysPatcher is a single static binary plus an optional unit file. This site documents the command line. Release tarballs are attached to tagged commits in the Git repository.SysPatcher — это один статический бинарник и необязательный unit-файл. На сайте описаны команды. Архивы релизов лежат у помеченных коммитов в git.

InstallУстановка

On Linux the bootstrap command prints the detected kernel and exits. It does not fetch a binary from syspatcher.com. Install from your own package build, or from a tag you have reviewed:На Linux команда установки печатает ядро и завершается. Бинарник с syspatcher.com она не качает. Ставьте свою сборку пакета или тег, который вы просмотрели:

curl -fsSL https://syspatcher.com/install.sh | sh
brew install syspatcher/tap/syspatcher
powershell -c "irm https://syspatcher.com/install.ps1 | iex"

After the binary is on PATH, confirm it:Когда бинарник есть в PATH, проверьте:

syspatcher version

Check, apply, roll backПроверка, применение, откат

check only reads. apply writes a journal entry before it changes a package. rollback uses that journal and will not invent a previous version it did not record.check только читает. apply сначала пишет запись в журнал, потом меняет пакет. rollback берёт этот журнал и не выдумывает версию, которой там не было.

syspatcher check --critical --cve-only
syspatcher apply --kernel --live --dry-run
syspatcher apply --confirm
syspatcher rollback --last

--dry-run prints the plan and does not touch the package database. --confirm is required for a real apply. A cron job that omits --confirm is a no-op.--dry-run печатает план и не трогает базу пакетов. Для настоящего применения нужен --confirm. Cron без --confirm ничего не делает.

Config fileФайл конфигурации

Default path: /etc/syspatcher/config.yaml. The fields used by 1.4 are:Путь по умолчанию: /etc/syspatcher/config.yaml. В версии 1.4 используются такие поля:

Offline CVE cacheОфлайн-кэш CVE

The cache lives in /var/lib/syspatcher/cve. syspatcher check uses it when the feed cannot be refreshed. The file header records the snapshot date, so a stale cache is visible in the report instead of being treated as current.Кэш лежит в /var/lib/syspatcher/cve. syspatcher check берёт его, если ленту не удалось обновить. В заголовке файла есть дата снимка, поэтому устаревший кэш виден в отчёте и не выдаётся за свежий.

Back to the project pageНа страницу проекта