瀏覽代碼

Add a bit of hardening to the systemd service

Tested in an unprivileged lxc container, so it shouldn't™ break anything.
Julien Voisin 3 年之前
父節點
當前提交
564990964d
共有 1 個文件被更改,包括 22 次插入0 次删除
  1. 22 0
      debian/jellyfin.service

+ 22 - 0
debian/jellyfin.service

@@ -10,5 +10,27 @@ ExecStart = /usr/bin/jellyfin ${JELLYFIN_WEB_OPT} ${JELLYFIN_RESTART_OPT} ${JELL
 Restart = on-failure
 TimeoutSec = 15
 
+NoNewPrivileges=true
+SystemCallArchitectures=native
+RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
+ProtectKernelModules=True
+SystemCallFilter=~@clock
+SystemCallFilter=~@aio
+SystemCallFilter=~@chown
+SystemCallFilter=~@cpu-emulation
+SystemCallFilter=~@debug
+SystemCallFilter=~@keyring
+SystemCallFilter=~@memlock
+SystemCallFilter=~@module
+SystemCallFilter=~@mount
+SystemCallFilter=~@obsolete
+SystemCallFilter=~@privileged
+SystemCallFilter=~@raw-io
+SystemCallFilter=~@reboot
+SystemCallFilter=~@setuid
+SystemCallFilter=~@swap
+SystemCallErrorNumber=EPERM
+
+
 [Install]
 WantedBy = multi-user.target