]> git.ipfire.org Git - thirdparty/util-linux.git/commit
fstrim: Add hardening settings to fstrim.service
authorAndreas Henriksson <andreas@fatal.se>
Thu, 22 Nov 2018 10:13:58 +0000 (11:13 +0100)
committerKarel Zak <kzak@redhat.com>
Thu, 22 Nov 2018 10:13:58 +0000 (11:13 +0100)
commit8f3d2d76aa3f5e20313362db6669dcd001bff26c
treec1bb2cf0839f54566df396a0a88b68fe622be2a3
parent3fa06e049012218d883d0e1251df86bafbc446bf
fstrim: Add hardening settings to fstrim.service

This limits what the fstrim process has access to when it runs.

PrivateUsers can't be enabled because of:
"If this mode is enabled, all unit processes are run without privileges
in the host user namespace[...]"

Further improving this with additional option or making
things even tighter is most likely possible.

Signed-off-by: Andreas Henriksson <andreas@fatal.se>
Signed-off-by: Karel Zak <kzak@redhat.com>
sys-utils/fstrim.service.in