From 45259b9bf80c82501ecd9179e143e5dd901854ac Mon Sep 17 00:00:00 2001 From: Michael Biebl Date: Tue, 19 Nov 2019 09:10:23 +0100 Subject: [PATCH] udev: drop SystemCallArchitectures=native from systemd-udevd.service We can't really control what helper programs are run from other udev rules. E.g. running i386 binaries under amd64 is a valid use case and should not trigger a SIGSYS failure. Closes: #869719 Gbp-Pq: Topic debian Gbp-Pq: Name udev-drop-SystemCallArchitectures-native-from-systemd-ude.patch --- units/systemd-udevd.service.in | 1 - 1 file changed, 1 deletion(-) diff --git a/units/systemd-udevd.service.in b/units/systemd-udevd.service.in index 225eac21..f541ff68 100644 --- a/units/systemd-udevd.service.in +++ b/units/systemd-udevd.service.in @@ -35,7 +35,6 @@ MemoryDenyWriteExecute=yes RestrictAddressFamilies=AF_UNIX AF_NETLINK AF_INET AF_INET6 RestrictRealtime=yes RestrictSUIDSGID=yes -SystemCallArchitectures=native LockPersonality=yes IPAddressDeny=any @SERVICE_WATCHDOG@ -- 2.30.2