mirror of
https://gitlab.torproject.org/tpo/core/tor.git
synced 2024-11-30 23:53:32 +01:00
systemd unit file: ensures that the process and all its children can never gain
new privileges (#12939).
This commit is contained in:
parent
b159ffb675
commit
b4170421cc
1
contrib/dist/tor.service.in
vendored
1
contrib/dist/tor.service.in
vendored
@ -19,6 +19,7 @@ PrivateTmp = yes
|
|||||||
DeviceAllow = /dev/null rw
|
DeviceAllow = /dev/null rw
|
||||||
DeviceAllow = /dev/urandom r
|
DeviceAllow = /dev/urandom r
|
||||||
InaccessibleDirectories = /home
|
InaccessibleDirectories = /home
|
||||||
|
NoNewPrivileges = yes
|
||||||
|
|
||||||
[Install]
|
[Install]
|
||||||
WantedBy = multi-user.target
|
WantedBy = multi-user.target
|
||||||
|
Loading…
Reference in New Issue
Block a user