[2/2] paccache.service.in: Restrict all (network) address families

Message ID 20211130125356.ivmvurk4uccmna6t@gmail.com
State New
Headers show
Series [1/2] paccache.service.in: Add @system-service to SystemCallFilter | expand

Commit Message

Frederik “Freso” S. Olesen Nov. 30, 2021, 12:53 p.m. UTC
RestrictAddressFamilies used to not have an option to restrict all
address families, but systemd 249 introduced a special value "none"
exactly for this purpose.

Signed-off-by: Frederik “Freso” S. Olesen <freso.dk@gmail.com>
---
 src/paccache.service.in | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Patch

diff --git a/src/paccache.service.in b/src/paccache.service.in
index a821daf..57390ea 100644
--- a/src/paccache.service.in
+++ b/src/paccache.service.in
@@ -28,7 +28,7 @@  ProtectKernelTunables=yes
 ProtectKernelModules=yes
 ProtectKernelLogs=yes
 ProtectControlGroups=yes
-RestrictAddressFamilies=AF_UNIX
+RestrictAddressFamilies=none
 RestrictNamespaces=yes
 LockPersonality=yes
 MemoryDenyWriteExecute=yes