chiark / gitweb /
units: add SecureBits
[elogind.git] / units / systemd-timesyncd.service.in
index 39edafc8d295d7b92536002144cdeac4f5dcb899..bc7aa26a9b7279782a36ba147032719b3f7c9f07 100644 (file)
@@ -23,6 +23,7 @@ Restart=always
 RestartSec=0
 ExecStart=@rootlibexecdir@/systemd-timesyncd
 CapabilityBoundingSet=CAP_SYS_TIME CAP_SETUID CAP_SETGID CAP_SETPCAP CAP_CHOWN CAP_DAC_OVERRIDE CAP_FOWNER
+SecureBits=noroot noroot-locked
 PrivateTmp=yes
 PrivateDevices=yes
 ProtectSystem=full