mirror of
https://git.kernel.org/pub/scm/network/wireless/iwd.git
synced 2024-11-22 14:39:39 +01:00
build: Start using CapabilityBoundingSet option from systemd
This commit is contained in:
parent
0f21157287
commit
e6a99f461a
@ -9,6 +9,7 @@ BusName=net.connman.iwd
|
|||||||
ExecStart=@libexecdir@/iwd
|
ExecStart=@libexecdir@/iwd
|
||||||
LimitNPROC=1
|
LimitNPROC=1
|
||||||
Restart=on-failure
|
Restart=on-failure
|
||||||
|
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_RAW
|
||||||
PrivateTmp=true
|
PrivateTmp=true
|
||||||
NoNewPrivileges=true
|
NoNewPrivileges=true
|
||||||
DevicePolicy=closed
|
DevicePolicy=closed
|
||||||
|
@ -9,6 +9,7 @@ BusName=net.connman.ead
|
|||||||
ExecStart=@libexecdir@/ead
|
ExecStart=@libexecdir@/ead
|
||||||
LimitNPROC=1
|
LimitNPROC=1
|
||||||
Restart=on-failure
|
Restart=on-failure
|
||||||
|
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_RAW
|
||||||
PrivateTmp=true
|
PrivateTmp=true
|
||||||
NoNewPrivileges=true
|
NoNewPrivileges=true
|
||||||
PrivateDevices=true
|
PrivateDevices=true
|
||||||
|
Loading…
Reference in New Issue
Block a user