Explorar o código

Merge pull request #6953 from matthiasdv/mdv/harden-systemd-service

Add more hardening to systemd service
Claus Vium %!s(int64=3) %!d(string=hai) anos
pai
achega
dd8b9e9d23
Modificáronse 1 ficheiros con 14 adicións e 1 borrados
  1. 14 1
      debian/jellyfin.service

+ 14 - 1
debian/jellyfin.service

@@ -13,7 +13,20 @@ TimeoutSec = 15
 NoNewPrivileges=true
 SystemCallArchitectures=native
 RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
-ProtectKernelModules=True
+RestrictNamespaces=true
+RestrictRealtime=true
+RestrictSUIDSGID=true
+ProtectClock=true
+ProtectControlGroups=true
+ProtectHostname=true
+ProtectKernelLogs=true
+ProtectKernelModules=true
+ProtectKernelTunables=true
+LockPersonality=true
+PrivateTmp=true
+PrivateDevices=false
+PrivateUsers=true
+RemoveIPC=true
 SystemCallFilter=~@clock
 SystemCallFilter=~@aio
 SystemCallFilter=~@chown