if !HAVE_SYSTEMD_SYSTEM_CALL_FILTER
$(AM_V_GEN)perl -ni -e 'print unless /^SystemCallFilter/' $@
endif
-if !HAVE_SYSTEMD_MEMORY_DENY_WRITE_EXECUTE
- $(AM_V_GEN)perl -ni -e 'print unless /^MemoryDenyWriteExecute/' $@
-endif
if !HAVE_SYSTEMD_PROTECT_PROC
$(AM_V_GEN)perl -ni -e 'print unless /^ProtectProc/' $@
endif
if !HAVE_SYSTEMD_PROTECT_PROC
$(AM_V_GEN)perl -ni -e 'print unless /^ProtectProc/' $@
endif
-if !HAVE_SYSTEMD_MEMORY_DENY_WRITE_EXECUTE
- $(AM_V_GEN)perl -ni -e 'print unless /^MemoryDenyWriteExecute/' $@
-endif
if !HAVE_SYSTEMD_PRIVATE_IPC
$(AM_V_GEN)perl -ni -e 'print unless /^PrivateIPC/' $@
endif
SystemCallArchitectures=native
SystemCallFilter=~ @clock @debug @module @mount @raw-io @reboot @swap @cpu-emulation @obsolete
ProtectProc=invisible
-MemoryDenyWriteExecute=true
PrivateIPC=true
RemoveIPC=true
DevicePolicy=closed
+# Not enabled by default because it does not play well with LuaJIT
+# MemoryDenyWriteExecute=true
[Install]
WantedBy=multi-user.target
SystemCallArchitectures=native
SystemCallFilter=~ @clock @debug @module @mount @raw-io @reboot @swap @cpu-emulation @obsolete
ProtectProc=invisible
-MemoryDenyWriteExecute=true
PrivateIPC=true
RemoveIPC=true
DevicePolicy=closed
+MemoryDenyWriteExecute=true
[Install]
WantedBy=multi-user.target
SystemCallArchitectures=native
SystemCallFilter=~ @clock @debug @module @mount @raw-io @reboot @swap @cpu-emulation @obsolete
ProtectProc=invisible
-MemoryDenyWriteExecute=true
PrivateIPC=true
RemoveIPC=true
DevicePolicy=closed
+# Not enabled by default because it does not play well with LuaJIT
+# MemoryDenyWriteExecute=true
[Install]
WantedBy=multi-user.target
if !HAVE_SYSTEMD_PROTECT_PROC
$(AM_V_GEN)perl -ni -e 'print unless /^ProtectProc/' $@
endif
-if !HAVE_SYSTEMD_MEMORY_DENY_WRITE_EXECUTE
- $(AM_V_GEN)perl -ni -e 'print unless /^MemoryDenyWriteExecute/' $@
-endif
if !HAVE_SYSTEMD_PRIVATE_IPC
$(AM_V_GEN)perl -ni -e 'print unless /^PrivateIPC/' $@
endif
SystemCallArchitectures=native
SystemCallFilter=~ @clock @debug @module @mount @raw-io @reboot @swap @cpu-emulation @obsolete
ProtectProc=invisible
-MemoryDenyWriteExecute=true
PrivateIPC=true
RemoveIPC=true
DevicePolicy=closed
+# Not enabled by default because it does not play well with LuaJIT
+# MemoryDenyWriteExecute=true
[Install]
WantedBy=multi-user.target