chiark / gitweb /
hostnamed: drop all caps but CAP_SYS_ADMIN
authorLennart Poettering <lennart@poettering.net>
Tue, 19 Apr 2011 04:07:29 +0000 (06:07 +0200)
committerLennart Poettering <lennart@poettering.net>
Tue, 19 Apr 2011 04:07:29 +0000 (06:07 +0200)
units/systemd-hostnamed.service.in

index 32a3ab5..6efab1e 100644 (file)
@@ -14,3 +14,4 @@ Description=Hostname Service
 ExecStart=@rootlibexecdir@/systemd-hostnamed
 Type=dbus
 BusName=org.freedesktop.hostname1
+CapabilityBoundingSet=CAP_SYS_ADMIN