fix: allow netlink for wildcard listener startup
TallyNote release / linux-x64 (push) Successful in 6m4s
TallyNote release / linux-x64 (push) Successful in 6m4s
This commit is contained in:
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "tallynote",
|
"name": "tallynote",
|
||||||
"version": "1.1.9",
|
"version": "1.1.10",
|
||||||
"private": true,
|
"private": true,
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"packageManager": "pnpm@9.0.6",
|
"packageManager": "pnpm@9.0.6",
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
set -Eeuo pipefail
|
set -Eeuo pipefail
|
||||||
root=$(cd "$(dirname "$0")/.." && pwd)
|
root=$(cd "$(dirname "$0")/.." && pwd)
|
||||||
bash -n "$root/install.sh" "$root/scripts/tallynote-update.sh"
|
bash -n "$root/install.sh" "$root/scripts/tallynote-update.sh"
|
||||||
|
grep -Eq '^RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK$' "$root/systemd/tallynote.service"
|
||||||
|
grep -Eq '^RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK$' "$root/systemd/tallynote-update.service"
|
||||||
output=$(bash "$root/install.sh" --dry-run --release-base-url https://releases.example.test/releases)
|
output=$(bash "$root/install.sh" --dry-run --release-base-url https://releases.example.test/releases)
|
||||||
grep -q 'dry-run' <<<"$output"
|
grep -q 'dry-run' <<<"$output"
|
||||||
grep -q '\[阶段\] 检查运行环境' <<<"$output"
|
grep -q '\[阶段\] 检查运行环境' <<<"$output"
|
||||||
|
|||||||
@@ -15,7 +15,9 @@ Environment=PATH=/usr/sbin:/usr/bin:/sbin:/bin
|
|||||||
NoNewPrivileges=true
|
NoNewPrivileges=true
|
||||||
CapabilityBoundingSet=
|
CapabilityBoundingSet=
|
||||||
AmbientCapabilities=
|
AmbientCapabilities=
|
||||||
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
|
# Keep the updater compatible with the same Node/libuv interface discovery
|
||||||
|
# path while retaining an explicit socket-family allowlist.
|
||||||
|
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
|
||||||
PrivateTmp=true
|
PrivateTmp=true
|
||||||
PrivateDevices=true
|
PrivateDevices=true
|
||||||
ProtectHome=true
|
ProtectHome=true
|
||||||
|
|||||||
@@ -20,7 +20,9 @@ ProtectSystem=strict
|
|||||||
InaccessiblePaths=/opt/tallynote/.update-work
|
InaccessiblePaths=/opt/tallynote/.update-work
|
||||||
ProtectHome=true
|
ProtectHome=true
|
||||||
PrivateDevices=true
|
PrivateDevices=true
|
||||||
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
|
# Fastify logs the addresses of wildcard listeners. Node's libuv uses the
|
||||||
|
# Linux netlink family while enumerating interfaces for that log message.
|
||||||
|
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
|
||||||
ProtectKernelTunables=true
|
ProtectKernelTunables=true
|
||||||
ProtectKernelModules=true
|
ProtectKernelModules=true
|
||||||
ProtectKernelLogs=true
|
ProtectKernelLogs=true
|
||||||
|
|||||||
Reference in New Issue
Block a user