From b0fd72a136a4ec36c54b5ae5c27479acb7e7a020 Mon Sep 17 00:00:00 2001 From: Dennis Fink Date: Sun, 20 Sep 2026 12:18:20 +0200 Subject: fix(systemd): allow pacman commands to run Remove syscall restrictions that prevent pacman and related subprocesses from running successfully under the systemd service. Also remove the outdated comment about ProtectSystem and ProtectHome. --- contrib/prometheus-pacman-exporter.service | 3 --- 1 file changed, 3 deletions(-) diff --git a/contrib/prometheus-pacman-exporter.service b/contrib/prometheus-pacman-exporter.service index 770295c..82b5854 100644 --- a/contrib/prometheus-pacman-exporter.service +++ b/contrib/prometheus-pacman-exporter.service @@ -17,7 +17,6 @@ ReadWritePaths=/var/lib/prometheus/node-exporter PrivateTmp=true # Mount a minimal /dev without the access to raw block or character devices PrivateDevices=true -# ProtectSystem and ProtectHome are ineffective for root and intentionally omitted # Hide other processes in /proc ProtectProc=invisible @@ -51,8 +50,6 @@ NoNewPrivileges=true # Syscall filtering SystemCallArchitectures=native SystemCallFilter=@system-service -SystemCallFilter=~@privileged @resources @mount @swap @reboot -SystemCallFilter=setfsuid setfsgid [Install] WantedBy=multi-user.target -- cgit v1.3.1