Преглед изворни кода

NoNewPrivileges breaks ability to send email via sendmail because it restricts ability to run setuid/setgid binaries

2298-weird-follow-issue
Mark Felder пре 3 година
родитељ
комит
e7b0840b88
1 измењених фајлова са 0 додато и 2 уклоњено
  1. +0
    -2
      installation/pleroma.service

+ 0
- 2
installation/pleroma.service Прегледај датотеку

@@ -31,8 +31,6 @@ ProtectHome=true
ProtectSystem=full
; Sets up a new /dev mount for the process and only adds API pseudo devices like /dev/null, /dev/zero or /dev/random but not physical devices. Disabled by default because it may not work on devices like the Raspberry Pi.
PrivateDevices=false
; Ensures that the service process and all its children can never gain new privileges through execve().
NoNewPrivileges=true
; Drops the sysadmin capability from the daemon.
CapabilityBoundingSet=~CAP_SYS_ADMIN



Loading…
Откажи
Сачувај