瀏覽代碼

Update log2ram.service

pull/195/head
TubbyCat 2 年之前
committed by GitHub
父節點
當前提交
69bc7a5cbe
沒有發現已知的金鑰在資料庫的簽署中 GPG Key ID: 4AEE18F83AFDEB23
共有 1 個文件被更改,包括 5 次插入5 次删除
  1. +5
    -5
      log2ram.service

+ 5
- 5
log2ram.service 查看文件

@@ -15,12 +15,12 @@ ExecReload= /usr/local/bin/log2ram write
TimeoutStartSec=120
RemainAfterExit=yes

#SANDBOXING# -- NEEDS TESTING
#SANDBOXING# -- partly tested
LockPersonality=true
MemoryDenyWriteExecute=true
NoNewPriviliges=true
#PrivateDevices=
#PrivateNetwork=true
PrivateDevices=true
PrivateNetwork=true
#Will likely break "MAIL" in log2ram.config if does not point to localhost / disabled
ProtectClock=true
ProtectControlGroups=true
@@ -29,8 +29,8 @@ ProtectKernelLogs=true
ProtectKernelModules=true
ProtectKernelTunables=true
RestrictSUIDSGID=true
ProtectSystem=full
# ALT: ProtectSystem=true # if-and-only-if needs /etc, but can whitelist dir prn
ProtectSystem=true
# ALT: ProtectSystem=full # needs rw whitelisting for /var/hdd.log/
ProtectHome=true
#will likely break situations wherein configured to also copy logs from $HOME.
#can probably fix with systemctl edit to whitelist relevant dirs


Loading…
取消
儲存