X-Git-Url: http://git.squeep.com/?a=blobdiff_plain;f=installation%2Fpleroma.service;h=f1ed56cb3c8dd9db857392840ae58650cf1e3cdb;hb=8a9f089812295ef5087864e852ad9550ee00ce76;hp=6955e5cc65cb08fde3c48e4d1ad6740da68c273a;hpb=fe2759bc9f2dad044b49f4954693ac09f9368041;p=akkoma diff --git a/installation/pleroma.service b/installation/pleroma.service index 6955e5cc6..f1ed56cb3 100644 --- a/installation/pleroma.service +++ b/installation/pleroma.service @@ -21,6 +21,8 @@ ProtectSystem=full PrivateDevices=false ; Ensures that the service process and all its children can never gain new privileges through execve(). NoNewPrivileges=true +; Drops the sysadmin capability from the daemon. +CapabilityBoundingSet=~CAP_SYS_ADMIN [Install] WantedBy=multi-user.target