Преглед на файлове

add more hardening to systemd service

matthiasdv преди 3 години
родител
ревизия
3176a4ddd9
променени са 1 файла, в които са добавени 14 реда и са изтрити 1 реда
  1. 14 1
      debian/jellyfin.service

+ 14 - 1
debian/jellyfin.service

@@ -13,7 +13,20 @@ TimeoutSec = 15
 NoNewPrivileges=true
 NoNewPrivileges=true
 SystemCallArchitectures=native
 SystemCallArchitectures=native
 RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
 RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
-ProtectKernelModules=True
+RestrictNamespaces=true
+RestrictRealtime=true
+RestrictSUIDSGID=true
+ProtectClock=true
+ProtectControlGroups=true
+ProtectHostname=true
+ProtectKernelLogs=true
+ProtectKernelModules=true
+ProtectKernelTunables=true
+LockPersonality=true
+PrivateTmp=true
+PrivateDevices=false
+PrivateUsers=true
+RemoveIPC=true
 SystemCallFilter=~@clock
 SystemCallFilter=~@clock
 SystemCallFilter=~@aio
 SystemCallFilter=~@aio
 SystemCallFilter=~@chown
 SystemCallFilter=~@chown