]> git.ipfire.org Git - thirdparty/lxc.git/commitdiff
Update gentoo.moresecure.conf.
authori.Dark_Templar <darktemplar@dark-templar-archives.net>
Sat, 2 Dec 2017 07:33:51 +0000 (10:33 +0300)
committerChristian Brauner <christian.brauner@ubuntu.com>
Sun, 17 Dec 2017 14:49:38 +0000 (15:49 +0100)
Closes https://github.com/lxc/lxc/issues/1928

Signed-off-by: i.Dark_Templar <darktemplar@dark-templar-archives.net>
config/templates/gentoo.moresecure.conf.in

index c08b91c1ab6eea49f52244c56c9f18eabc85e1b7..aa7c625ccfa7b2e9f53121bc9f00eaf5eeabb754 100644 (file)
@@ -30,7 +30,8 @@ lxc.mount.entry=run run tmpfs rw,nosuid,nodev,relatime,mode=755 0 0
 # lxc.cap.drop = audit_write
 # lxc.cap.drop = setpcap          # breaks journald
 # lxc.cap.drop = sys_resource     # breaks systemd
-lxc.cap.drop = audit_control audit_write dac_read_search fsetid ipc_owner linux_immutable mknod setfcap setpcap sys_admin sys_boot sys_nice sys_pacct sys_ptrace sys_rawio sys_resource sys_tty_config syslog
+# lxc.cap.drop = sys_boot         # breaks sysvinit
+lxc.cap.drop = audit_control audit_write dac_read_search fsetid ipc_owner linux_immutable mknod setfcap setpcap sys_admin sys_nice sys_pacct sys_ptrace sys_rawio sys_resource sys_tty_config syslog
 
 # WARNING: the security vulnerability reported for 'cap_net_admin' at
 # http://mainisusuallyafunction.blogspot.com/2012/11/attacking-hardened-linux-systems-with.html