Merge remote-tracking branch 'intrigeri/bug12939-systemd-no-new-privileges'

Conflicts:
	contrib/dist/tor.service.in
This commit is contained in:
Nick Mathewson 2014-09-03 13:29:43 -04:00
commit 54348201f7
2 changed files with 5 additions and 0 deletions

View File

@ -0,0 +1,4 @@
o Distribution:
- systemd unit file: ensures that the process and all its children
can never gain new privileges.
Patch by intrigeri; resolves ticket 12939.

View File

@ -22,6 +22,7 @@ InaccessibleDirectories = /home
ReadOnlyDirectories = /
ReadWriteDirectories = @LOCALSTATEDIR@/lib/tor
ReadWriteDirectories = @LOCALSTATEDIR@/log/tor
NoNewPrivileges = yes
[Install]
WantedBy = multi-user.target