forked from cybrespace/mastodon
		
	templates/systemd/mastodon: optimize SystemCallFilters (#16127)
This commit is contained in:
		
							parent
							
								
									0bc909687a
								
							
						
					
					
						commit
						7da104eb11
					
				
					 2 changed files with 2 additions and 2 deletions
				
			
		
							
								
								
									
										2
									
								
								dist/mastodon-sidekiq.service
									
										
									
									
										vendored
									
									
								
							
							
						
						
									
										2
									
								
								dist/mastodon-sidekiq.service
									
										
									
									
										vendored
									
									
								
							| 
						 | 
				
			
			@ -38,7 +38,7 @@ PrivateMounts=true
 | 
			
		|||
ProtectClock=true
 | 
			
		||||
# System Call Filtering
 | 
			
		||||
SystemCallArchitectures=native
 | 
			
		||||
SystemCallFilter=~@clock @cpu-emulation @debug @keyring @module @mount @obsolete @privileged @raw-io @reboot @resources @setuid @swap
 | 
			
		||||
SystemCallFilter=~@clock @cpu-emulation @debug @keyring @module @mount @obsolete @raw-io @reboot @setuid @swap
 | 
			
		||||
 | 
			
		||||
[Install]
 | 
			
		||||
WantedBy=multi-user.target
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
							
								
								
									
										2
									
								
								dist/mastodon-web.service
									
										
									
									
										vendored
									
									
								
							
							
						
						
									
										2
									
								
								dist/mastodon-web.service
									
										
									
									
										vendored
									
									
								
							| 
						 | 
				
			
			@ -38,7 +38,7 @@ PrivateMounts=true
 | 
			
		|||
ProtectClock=true
 | 
			
		||||
# System Call Filtering
 | 
			
		||||
SystemCallArchitectures=native
 | 
			
		||||
SystemCallFilter=~@clock @cpu-emulation @debug @keyring @module @mount @obsolete @privileged @raw-io @reboot @resources @setuid @swap
 | 
			
		||||
SystemCallFilter=~@clock @cpu-emulation @debug @keyring @module @mount @obsolete @raw-io @reboot @resources @setuid @swap
 | 
			
		||||
 | 
			
		||||
[Install]
 | 
			
		||||
WantedBy=multi-user.target
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
		Loading…
	
	Add table
		
		Reference in a new issue