X-Git-Url: http://git.squeep.com/?a=blobdiff_plain;f=installation%2Fpleroma.service;h=f1ed56cb3c8dd9db857392840ae58650cf1e3cdb;hb=ce2efd1ee25d6e06c4bc5c0d97aad7b84c7c6874;hp=6955e5cc65cb08fde3c48e4d1ad6740da68c273a;hpb=c3f562a611c71fb07d4afa6ad6054eda4583f36f;p=akkoma diff --git a/installation/pleroma.service b/installation/pleroma.service index 6955e5cc6..f1ed56cb3 100644 --- a/installation/pleroma.service +++ b/installation/pleroma.service @@ -21,6 +21,8 @@ ProtectSystem=full PrivateDevices=false ; Ensures that the service process and all its children can never gain new privileges through execve(). NoNewPrivileges=true +; Drops the sysadmin capability from the daemon. +CapabilityBoundingSet=~CAP_SYS_ADMIN [Install] WantedBy=multi-user.target