set ProtectProc,ProcSubset
This commit is contained in:
parent
9b6bc98086
commit
02098c63d4
|
@ -19,7 +19,8 @@ CapabilityBoundingSet=
|
|||
CapabilityBoundingSet=~CAP_SYS_ADMIN CAP_SYS_BOOT CAP_SYS_CHROOT CAP_AUDIT_*
|
||||
|
||||
SystemCallFilter=~memfd_create @reboot @swap @resources @cpu-emulation @debug @module @clock @raw-io @obsolete
|
||||
# ProtectProc=invisible
|
||||
ProtectProc=invisible
|
||||
ProcSubset=pid
|
||||
ProtectHome=true
|
||||
RestrictNamespaces=uts ipc pid user cgroup
|
||||
NoNewPrivileges=True
|
||||
|
|
Loading…
Reference in New Issue