fix: allow netlink for wildcard listener startup
TallyNote release / linux-x64 (push) Successful in 6m4s

This commit is contained in:
Qiufeng
2026-09-02 14:06:49 +08:00
parent 37ffc27ff5
commit 1925676fc9
4 changed files with 9 additions and 3 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "tallynote",
"version": "1.1.9",
"version": "1.1.10",
"private": true,
"type": "module",
"packageManager": "pnpm@9.0.6",
+2
View File
@@ -2,6 +2,8 @@
set -Eeuo pipefail
root=$(cd "$(dirname "$0")/.." && pwd)
bash -n "$root/install.sh" "$root/scripts/tallynote-update.sh"
grep -Eq '^RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK$' "$root/systemd/tallynote.service"
grep -Eq '^RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK$' "$root/systemd/tallynote-update.service"
output=$(bash "$root/install.sh" --dry-run --release-base-url https://releases.example.test/releases)
grep -q 'dry-run' <<<"$output"
grep -q '\[阶段\] 检查运行环境' <<<"$output"
+3 -1
View File
@@ -15,7 +15,9 @@ Environment=PATH=/usr/sbin:/usr/bin:/sbin:/bin
NoNewPrivileges=true
CapabilityBoundingSet=
AmbientCapabilities=
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
# Keep the updater compatible with the same Node/libuv interface discovery
# path while retaining an explicit socket-family allowlist.
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
PrivateTmp=true
PrivateDevices=true
ProtectHome=true
+3 -1
View File
@@ -20,7 +20,9 @@ ProtectSystem=strict
InaccessiblePaths=/opt/tallynote/.update-work
ProtectHome=true
PrivateDevices=true
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
# Fastify logs the addresses of wildcard listeners. Node's libuv uses the
# Linux netlink family while enumerating interfaces for that log message.
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
ProtectKernelTunables=true
ProtectKernelModules=true
ProtectKernelLogs=true