%PDF- <> %âãÏÓ endobj 2 0 obj <> endobj 3 0 obj <>/ExtGState<>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI] >>/Annots[ 28 0 R 29 0 R] /MediaBox[ 0 0 595.5 842.25] /Contents 4 0 R/Group<>/Tabs/S>> endobj ºaâÚÎΞ-ÌE1ÍØÄ÷{òò2ÿ ÛÖ^ÔÀá TÎ{¦?§®¥kuµùÕ5sLOšuY>endobj 2 0 obj<>endobj 2 0 obj<>endobj 2 0 obj<>endobj 2 0 obj<> endobj 2 0 obj<>endobj 2 0 obj<>es 3 0 R>> endobj 2 0 obj<> ox[ 0.000000 0.000000 609.600000 935.600000]/Fi endobj 3 0 obj<> endobj 7 1 obj<>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI]>>/Subtype/Form>> stream
# APT News is hosted at https://motd.ubuntu.com/aptnews.json and can include # timely information related to apt updates available to your system. # This service runs in the background during an `apt update` to download the # latest news and set it to appear in the output of the next `apt upgrade`. # The script won't do anything if you've run: `pro config set apt_news=false`. # The script will limit network requests to at most once per 24 hours. # You can also host your own aptnews.json and configure your system to use it # with the command: # `pro config set apt_news_url=https://yourhostname/path/to/aptnews.json` [Unit] Description=Update APT News [Service] Type=oneshot ExecStart=/usr/bin/python3 /usr/lib/ubuntu-advantage/apt_news.py AppArmorProfile=-ubuntu_pro_apt_news CapabilityBoundingSet=~CAP_SYS_ADMIN CapabilityBoundingSet=~CAP_NET_ADMIN CapabilityBoundingSet=~CAP_NET_BIND_SERVICE CapabilityBoundingSet=~CAP_SYS_PTRACE CapabilityBoundingSet=~CAP_NET_RAW PrivateTmp=true RestrictAddressFamilies=~AF_NETLINK RestrictAddressFamilies=~AF_PACKET # These may break some tests, and should be enabled carefully #NoNewPrivileges=true #PrivateDevices=true #ProtectControlGroups=true # ProtectHome=true seems to reliably break the GH integration test with a lunar lxd on jammy host #ProtectHome=true #ProtectKernelModules=true #ProtectKernelTunables=true #ProtectSystem=full #RestrictSUIDSGID=true # Unsupported in bionic # Suggestion from systemd.exec(5) manpage on SystemCallFilter #SystemCallFilter=@system-service #SystemCallFilter=~@mount #SystemCallErrorNumber=EPERM #ProtectClock=true #ProtectKernelLogs=true