]> git.ipfire.org Git - thirdparty/tor.git/commitdiff
systemd unit file: ensures that the process and all its children can never gain
authorintrigeri <intrigeri@boum.org>
Wed, 27 Aug 2014 03:18:26 +0000 (03:18 +0000)
committerintrigeri <intrigeri@boum.org>
Wed, 27 Aug 2014 03:18:26 +0000 (03:18 +0000)
new privileges (#12939).

contrib/dist/tor.service.in

index 2fe51c75d912d276e761359e42aaa645abc9d107..c4709a7fd6ece2d82a1ac2e709b9b75545ef01f9 100644 (file)
@@ -19,6 +19,7 @@ PrivateTmp = yes
 DeviceAllow = /dev/null rw
 DeviceAllow = /dev/urandom r
 InaccessibleDirectories = /home
+NoNewPrivileges = yes
 
 [Install]
 WantedBy = multi-user.target