From a2cefa14ee11e5657c31dfe9493a0de7e81ecfef Mon Sep 17 00:00:00 2001 From: Matt Mix Date: Mon, 24 Jun 2024 13:55:27 -0500 Subject: [PATCH] Add AF_UNIX to RestrictAddressFamilies AF_UNIX is needed so that cgroup_exporter can get user information from sss. --- packaging/rpm/cgroup_exporter.service | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packaging/rpm/cgroup_exporter.service b/packaging/rpm/cgroup_exporter.service index 46b025f..adf74a6 100644 --- a/packaging/rpm/cgroup_exporter.service +++ b/packaging/rpm/cgroup_exporter.service @@ -18,7 +18,7 @@ ProtectHome=yes ProtectControlGroups=yes ProtectKernelModules=yes ProtectKernelTunables=yes -RestrictAddressFamilies=AF_INET AF_INET6 +RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX RestrictNamespaces=yes RestrictRealtime=yes RestrictSUIDSGID=yes