Date: Monday, February 24, 2020 @ 20:50:09 Author: jelle Revision: 376165
upgpkg: prometheus-node-exporter 0.18.1-4 Change ProtectHome to read-only so systemd can view mount points in /home no files should be accesible as the node exporter runs as a different user. Resolves FS#62677 Modified: prometheus-node-exporter/trunk/PKGBUILD prometheus-node-exporter/trunk/prometheus-node-exporter.service ----------------------------------+ PKGBUILD | 6 +++--- prometheus-node-exporter.service | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) Modified: PKGBUILD =================================================================== --- PKGBUILD 2020-02-24 20:32:07 UTC (rev 376164) +++ PKGBUILD 2020-02-24 20:50:09 UTC (rev 376165) @@ -2,7 +2,7 @@ pkgname=prometheus-node-exporter pkgver=0.18.1 -pkgrel=3 +pkgrel=4 pkgdesc='Exporter for machine metrics' url='https://github.com/prometheus/node_exporter' @@ -14,7 +14,7 @@ backup=('etc/conf.d/prometheus-node-exporter') -source=("https://github.com/prometheus/node_exporter/archive/v$pkgver.tar.gz" +source=("$pkgname-$pkgver.tar.gz::https://github.com/prometheus/node_exporter/archive/v$pkgver.tar.gz" prometheus-node-exporter.conf prometheus-node-exporter.service prometheus-node-exporter.sysusers) @@ -21,7 +21,7 @@ sha256sums=('9ddf187c462f2681ab4516410ada0e6f0f03097db6986686795559ea71a07694' 'ce93e2b95bfc86a8a046e2f9175408e1cbffa784fd3b65dd141fde70b5bb2585' - '727ed5df3395fd77d8e2ae8c3ab7a6352213655e38c9b37badfea1aa90556394' + '457e305760323f941d20248e2ca5817ae4a8b5586f79a2331b968bf3baa66c5b' 'c7fd0b1793dfe7a354a28e978d3c79e7195eaf43376b9eece37e996fe0772c5c') build() { Modified: prometheus-node-exporter.service =================================================================== --- prometheus-node-exporter.service 2020-02-24 20:32:07 UTC (rev 376164) +++ prometheus-node-exporter.service 2020-02-24 20:50:09 UTC (rev 376165) @@ -11,7 +11,7 @@ ExecStart=/usr/bin/prometheus-node-exporter $NODE_EXPORTER_ARGS ExecReload=/bin/kill -HUP $MAINPID NoNewPrivileges=true -ProtectHome=true +ProtectHome=read-only ProtectSystem=strict [Install]
