1
0
mirror of https://github.com/systemd/systemd.git synced 2025-03-06 00:58:29 +03:00
Lennart Poettering 417116f234 core: add new ReadOnlySystem= and ProtectedHome= settings for service units
ReadOnlySystem= uses fs namespaces to mount /usr and /boot read-only for
a service.

ProtectedHome= uses fs namespaces to mount /home and /run/user
inaccessible or read-only for a service.

This patch also enables these settings for all our long-running services.

Together they should be good building block for a minimal service
sandbox, removing the ability for services to modify the operating
system or access the user's private data.
2014-06-03 23:57:51 +02:00
..
2013-12-25 22:53:45 -05:00
2013-07-03 08:19:20 -04:00
2014-02-20 22:43:27 -05:00
2013-07-03 08:19:20 -04:00
2013-07-03 08:19:20 -04:00
2014-02-20 22:43:27 -05:00
2014-02-17 19:03:07 -05:00
2014-02-20 22:43:27 -05:00
2014-02-20 22:43:27 -05:00
2014-02-20 22:43:27 -05:00
2014-02-20 22:43:27 -05:00
2014-02-20 22:43:27 -05:00
2014-02-20 22:43:27 -05:00
2014-02-20 22:43:27 -05:00
2014-05-15 13:23:55 +02:00
2014-02-17 19:03:07 -05:00
2013-12-25 22:53:45 -05:00
2014-02-17 19:03:07 -05:00
2014-02-20 22:43:27 -05:00