From d9f1245503e5a6d72132f2408223e65c66218a6f Mon Sep 17 00:00:00 2001 From: fuleyi Date: Thu, 3 Sep 2026 15:05:26 +0800 Subject: [PATCH] chore: harden app-update-notifier systemd service sandbox MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 1. Enable ProtectHome to hide user home directories from the service. 2. Enable PrivateTmp to give the service an isolated private /tmp. 3. Service only talks to the system bus, so sandboxing has no impact. Log: No user-facing changes Influence: 1. Install the package and verify the unit contains the new sandbox options. 2. Trigger a dpkg post-invoke and confirm the ApplicationUpdated signal is still emitted. 3. Confirm app-update-notifier starts and exits cleanly under the hardened sandbox. chore: 加固app-update-notifier服务的systemd安全沙箱 1. 启用ProtectHome,隐藏服务命名空间中的用户主目录。 2. 启用PrivateTmp,为服务提供独立的私有临时目录。 3. 服务仅通过系统总线通信,沙箱加固不影响其功能。 Log: 无用户可见变化 PMS: BUG-376055 Influence: 1. 安装包后检查服务单元包含新的沙箱选项。 2. 触发dpkg post-invoke,确认ApplicationUpdated信号仍正常发出。 3. 确认app-update-notifier在加固沙箱下正常启动并退出。 --- .../org.desktopspec.ApplicationUpdateNotifier1.service.in | 2 ++ 1 file changed, 2 insertions(+) diff --git a/apps/app-update-notifier/misc/systemd/system/org.desktopspec.ApplicationUpdateNotifier1.service.in b/apps/app-update-notifier/misc/systemd/system/org.desktopspec.ApplicationUpdateNotifier1.service.in index 88ba1643..9007e594 100644 --- a/apps/app-update-notifier/misc/systemd/system/org.desktopspec.ApplicationUpdateNotifier1.service.in +++ b/apps/app-update-notifier/misc/systemd/system/org.desktopspec.ApplicationUpdateNotifier1.service.in @@ -14,6 +14,8 @@ ExecStart=@CMAKE_INSTALL_FULL_LIBEXECDIR@/deepin/application-manager/app-update- # Security hardening ProtectSystem=strict +ProtectHome=yes +PrivateTmp=yes PrivateNetwork=yes RestrictAddressFamilies=AF_UNIX NoNewPrivileges=yes