mirror of
https://github.com/MengMengCode/VoCat.git
synced 2026-08-13 03:13:43 +08:00
fix: allow verified in-place updates
This commit is contained in:
@@ -7,8 +7,8 @@
|
||||
// Trust model: GitHub TLS guarantees the channel; the repository owner controls
|
||||
// which assets are published; SHA256SUMS guards integrity. There is no GPG
|
||||
// signature verification — an accepted trade-off for a closed-network testing
|
||||
// tool. The web UI's check-update button remains an intentional no-op; only the
|
||||
// CLI performs code replacement.
|
||||
// tool. Both the CLI and authenticated web UI use this same verified replacement
|
||||
// path.
|
||||
package update
|
||||
|
||||
import (
|
||||
|
||||
+3
-1
@@ -229,7 +229,9 @@ ProtectKernelLogs=true
|
||||
ProtectKernelModules=true
|
||||
ProtectKernelTunables=true
|
||||
ProtectControlGroups=true
|
||||
ReadWritePaths=/opt/vocat/data
|
||||
# The web/CLI self-updater verifies a release in this directory and atomically
|
||||
# renames it over the running binary. Keep the rest of the host read-only.
|
||||
ReadWritePaths=/opt/vocat/data /opt/vocat/bin
|
||||
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
|
||||
RestrictRealtime=true
|
||||
LockPersonality=true
|
||||
|
||||
Reference in New Issue
Block a user