]> git.ipfire.org Git - thirdparty/pdns.git/commitdiff
fixing #3748
authorRoman Hochuli <roman.hochuli@nexellent.ch>
Fri, 22 Apr 2016 09:19:41 +0000 (11:19 +0200)
committerRoman Hochuli <roman.hochuli@nexellent.ch>
Fri, 22 Apr 2016 09:19:41 +0000 (11:19 +0200)
contrib/systemd-pdns.service

index a60298c766a5d107fe295468b56894deb14a56f9..3d54e3220260bfacd0e38894f5db9a6c4033a11f 100644 (file)
@@ -11,7 +11,7 @@ Restart=on-failure
 StartLimitInterval=0
 PrivateTmp=true
 PrivateDevices=true
-CapabilityBoundingSet=CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID
+CapabilityBoundingSet=CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_CHROOT
 NoNewPrivileges=true
 # ProtectSystem=full will disallow write access to /etc and /usr, possibly
 # not being able to write slaved-zones into sqlite3 or zonefiles.