From: Mark Felder Date: Fri, 23 Oct 2020 20:32:32 +0000 (-0500) Subject: NoNewPrivileges breaks ability to send email via sendmail because it restricts abilit... X-Git-Url: https://git.squeep.com/?a=commitdiff_plain;h=e7b0840b88838f9e14bd2b09060d89c4a656966c;p=akkoma NoNewPrivileges breaks ability to send email via sendmail because it restricts ability to run setuid/setgid binaries --- diff --git a/installation/pleroma.service b/installation/pleroma.service index ee00a3b7a..63e83ed6e 100644 --- a/installation/pleroma.service +++ b/installation/pleroma.service @@ -31,8 +31,6 @@ ProtectHome=true ProtectSystem=full ; Sets up a new /dev mount for the process and only adds API pseudo devices like /dev/null, /dev/zero or /dev/random but not physical devices. Disabled by default because it may not work on devices like the Raspberry Pi. PrivateDevices=false -; Ensures that the service process and all its children can never gain new privileges through execve(). -NoNewPrivileges=true ; Drops the sysadmin capability from the daemon. CapabilityBoundingSet=~CAP_SYS_ADMIN