tighten Capabilities and SystemCallFilter list
This commit is contained in:
parent
1d34e711f6
commit
9b6bc98086
@ -16,6 +16,9 @@ IOSchedulingClass=1
|
||||
IOSchedulingPriority=0
|
||||
|
||||
CapabilityBoundingSet=
|
||||
CapabilityBoundingSet=~CAP_SYS_ADMIN CAP_SYS_BOOT CAP_SYS_CHROOT CAP_AUDIT_*
|
||||
|
||||
SystemCallFilter=~memfd_create @reboot @swap @resources @cpu-emulation @debug @module @clock @raw-io @obsolete
|
||||
# ProtectProc=invisible
|
||||
ProtectHome=true
|
||||
RestrictNamespaces=uts ipc pid user cgroup
|
||||
|
Loading…
Reference in New Issue
Block a user