1
0
Fork 0
mirror of https://gitlab.postmarketos.org/postmarketOS/pmaports.git synced 2025-07-17 02:35:11 +03:00
pmaports/temp/iio-sensor-proxy/0007-data-iio-sensor-proxy.service.in-add-AF_QIPCRTR.patch
Dylan Van Assche af17d8f3a7
temp/iio-sensor-proxy: upgrade libssc patches (MR 6040)
Libssc integration in iio-sensor-proxy has been heavily improved, sync the patches in pmaports.
2025-02-04 23:07:36 +09:00

29 lines
1 KiB
Diff

From 4522c9a8e07e6645c0c460d93cd57c67768fae71 Mon Sep 17 00:00:00 2001
From: Dylan Van Assche <me@dylanvanassche.be>
Date: Sat, 1 Jun 2024 21:15:15 +0200
Subject: [PATCH 07/10] data: iio-sensor-proxy.service.in: add AF_QIPCRTR
Allow AF_QIPCRTR in lockdown for libssc.
Libssc uses the QMI protocol over QRTR in the kernel.
Systemd limits the address families to UNIX, LOCAL, and NETLINK.
However, QRTR uses its own address family: AF_QIPCRTR.
Add it to the allowed families.
---
data/iio-sensor-proxy.service.in | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/data/iio-sensor-proxy.service.in b/data/iio-sensor-proxy.service.in
index 4bc921b..29ea3c0 100644
--- a/data/iio-sensor-proxy.service.in
+++ b/data/iio-sensor-proxy.service.in
@@ -14,6 +14,6 @@ ProtectControlGroups=true
ProtectHome=true
ProtectKernelModules=true
PrivateTmp=true
-RestrictAddressFamilies=AF_UNIX AF_LOCAL AF_NETLINK
+RestrictAddressFamilies=AF_UNIX AF_LOCAL AF_NETLINK AF_QIPCRTR
MemoryDenyWriteExecute=true
RestrictRealtime=true
--
2.47.1