mirror of
https://github.com/systemd/systemd-stable.git
synced 2024-12-22 13:33:56 +03:00
journal: limit caps we pass to journald
This commit is contained in:
parent
cea6691857
commit
ccd07a083e
2
NEWS
2
NEWS
@ -16,6 +16,8 @@ CHANGES WITH 41:
|
||||
understood to set system wide environment variables
|
||||
dynamically at boot.
|
||||
|
||||
* We now limit the set of capabilities of systemd-journald.
|
||||
|
||||
Contributions from: Benjamin Franzke, Kay Sievers, Lennart
|
||||
Poettering, Michael Olbrich, Michal Schmidt, Tom Gundersen,
|
||||
William Douglas
|
||||
|
@ -18,7 +18,7 @@ After=syslog.socket
|
||||
ExecStart=@rootlibexecdir@/systemd-journald
|
||||
NotifyAccess=all
|
||||
StandardOutput=null
|
||||
#CapabilityBoundingSet=CAP_SYS_ADMIN CAP_SETUID CAP_SETGID CAP_DAC_OVERRIDE
|
||||
CapabilityBoundingSet=CAP_SYS_ADMIN CAP_DAC_OVERRIDE CAP_SYS_PTRACE CAP_SYSLOG CAP_AUDIT_CONTROL CAP_CHOWN CAP_DAC_READ_SEARCH CAP_FOWNER
|
||||
|
||||
# Increase the default a bit in order to allow many simultaneous
|
||||
# services being run since we keep one fd open per service.
|
||||
|
Loading…
Reference in New Issue
Block a user