Add no_new_privs hardening to OpenRC and systemd service files #575

Merged
floatingghost merged 3 commits from norm/akkoma:no-new-privs into develop 2023-07-27 12:54:45 +00:00
Showing only changes of commit a86b010e10 - Show all commits

View file

@ -38,6 +38,8 @@ ProtectHome=true
ProtectSystem=full
; Sets up a new /dev mount for the process and only adds API pseudo devices like /dev/null, /dev/zero or /dev/random but not physical devices. Disabled by default because it may not work on devices like the Raspberry Pi.
PrivateDevices=false
; Ensures that the service process and all its children can never gain new privileges through execve().
NoNewPrivileges=true
; Drops the sysadmin capability from the daemon.
CapabilityBoundingSet=~CAP_SYS_ADMIN