mirror of
https://gitlab.torproject.org/tpo/core/tor.git
synced 2024-11-30 15:43:32 +01:00
Merge remote-tracking branch 'public/bug16162_026'
This commit is contained in:
commit
0a329a7a05
5
changes/bug16162
Normal file
5
changes/bug16162
Normal file
@ -0,0 +1,5 @@
|
||||
|
||||
o Minor bugfixes (systemd):
|
||||
- Tor's systemd unit file no longer contains extraneous spaces.
|
||||
These spaces would sometimes confuse tools like deb-systemd-helper.
|
||||
Fixes bug 16162; bugfix on 0.2.5.5-alpha.
|
44
contrib/dist/tor.service.in
vendored
44
contrib/dist/tor.service.in
vendored
@ -5,31 +5,31 @@
|
||||
# for your tor.service; it is not the last point.
|
||||
|
||||
[Unit]
|
||||
Description = Anonymizing overlay network for TCP
|
||||
After = syslog.target network.target nss-lookup.target
|
||||
Description=Anonymizing overlay network for TCP
|
||||
After=syslog.target network.target nss-lookup.target
|
||||
|
||||
[Service]
|
||||
Type = notify
|
||||
NotifyAccess = all
|
||||
ExecStartPre = @BINDIR@/tor -f @CONFDIR@/torrc --verify-config
|
||||
ExecStart = @BINDIR@/tor -f @CONFDIR@/torrc
|
||||
ExecReload = /bin/kill -HUP ${MAINPID}
|
||||
KillSignal = SIGINT
|
||||
TimeoutSec = 30
|
||||
Restart = on-failure
|
||||
WatchdogSec = 1m
|
||||
LimitNOFILE = 32768
|
||||
Type=notify
|
||||
NotifyAccess=all
|
||||
ExecStartPre=@BINDIR@/tor -f @CONFDIR@/torrc --verify-config
|
||||
ExecStart=@BINDIR@/tor -f @CONFDIR@/torrc
|
||||
ExecReload=/bin/kill -HUP ${MAINPID}
|
||||
KillSignal=SIGINT
|
||||
TimeoutSec=30
|
||||
Restart=on-failure
|
||||
WatchdogSec=1m
|
||||
LimitNOFILE=32768
|
||||
|
||||
# Hardening
|
||||
PrivateTmp = yes
|
||||
PrivateDevices = yes
|
||||
ProtectHome = yes
|
||||
ProtectSystem = full
|
||||
ReadOnlyDirectories = /
|
||||
ReadWriteDirectories = -@LOCALSTATEDIR@/lib/tor
|
||||
ReadWriteDirectories = -@LOCALSTATEDIR@/log/tor
|
||||
NoNewPrivileges = yes
|
||||
CapabilityBoundingSet = CAP_SETUID CAP_SETGID CAP_NET_BIND_SERVICE
|
||||
PrivateTmp=yes
|
||||
PrivateDevices=yes
|
||||
ProtectHome=yes
|
||||
ProtectSystem=full
|
||||
ReadOnlyDirectories=/
|
||||
ReadWriteDirectories=-@LOCALSTATEDIR@/lib/tor
|
||||
ReadWriteDirectories=-@LOCALSTATEDIR@/log/tor
|
||||
NoNewPrivileges=yes
|
||||
CapabilityBoundingSet=CAP_SETUID CAP_SETGID CAP_NET_BIND_SERVICE
|
||||
|
||||
[Install]
|
||||
WantedBy = multi-user.target
|
||||
WantedBy=multi-user.target
|
||||
|
Loading…
Reference in New Issue
Block a user