chiark / gitweb /
units: make use of PrivateTmp=yes and PrivateDevices=yes for all our long-running...
[elogind.git] / units / systemd-bus-proxyd@.service.in
index 93d6563201f55d40384601e82bdd3d5ce3a51ee1..1a6458ac5795f0192bb7980ada7b837051c96eff 100644 (file)
@@ -5,8 +5,15 @@
 #  the Free Software Foundation; either version 2.1 of the License, or
 #  (at your option) any later version.
 
-[Description]
+[Unit]
 Description=Legacy D-Bus Protocol Compatibility Daemon
 
 [Service]
-ExecStart=@rootlibexecdir@/systemd-bus-proxyd
+# The first argument will be replaced by the service by information on
+# the process requesting the proxy, we need a placeholder to keep the
+# space available for this.
+ExecStart=@rootlibexecdir@/systemd-bus-proxyd xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
+NotifyAccess=main
+CapabilityBoundingSet=CAP_IPC_OWNER
+PrivateTmp=yes
+PrivateDevices=yes