From c51cbfdcc7f38438553e4c2c60499f6aea7cc504 Mon Sep 17 00:00:00 2001 From: Lennart Poettering Date: Tue, 27 Jan 2015 02:19:33 +0100 Subject: [PATCH] man: document that ProtectSystem= also covers /boot --- man/systemd.exec.xml | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/man/systemd.exec.xml b/man/systemd.exec.xml index b338899d8..cbaec9f13 100644 --- a/man/systemd.exec.xml +++ b/man/systemd.exec.xml @@ -1064,13 +1064,14 @@ argument or full. If true, mounts the /usr - directory read-only for processes + and /boot + directories read-only for processes invoked by this unit. If set to full, the - /etc directory is mounted - read-only, too. This setting ensures - that any modification of the vendor - supplied operating system (and + /etc directory is + mounted read-only, too. This setting + ensures that any modification of the + vendor supplied operating system (and optionally its configuration) is prohibited for the service. It is recommended to enable this setting for -- 2.30.2