X-Git-Url: https://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?p=elogind.git;a=blobdiff_plain;f=man%2Fsystemd.exec.xml;h=f4caccdd23ada352ab2f8c36c50c888a252aa7cc;hp=610c821dc095025117444e72bb5d9cfee1964970;hb=82adf6af7c72b852449346835f33184a841b4796;hpb=c5b37953b7835562348d71ad5514faefa4cfb10b
diff --git a/man/systemd.exec.xml b/man/systemd.exec.xml
index 610c821dc..f4caccdd2 100644
--- a/man/systemd.exec.xml
+++ b/man/systemd.exec.xml
@@ -894,6 +894,24 @@
for details.
+
+ PrivateDevices=
+
+ Takes a boolean
+ argument. If true, sets up a new /dev
+ namespace for the executed processes
+ and only adds API pseudo devices such
+ as /dev/null,
+ /dev/zero or
+ /dev/random to
+ it, but no physical devices such as
+ /dev/sda. This is
+ useful to securely turn off physical
+ device access by the executed
+ process. Defaults to
+ false.
+
+
MountFlags=
@@ -932,6 +950,23 @@
this service.
+
+ SELinuxContext=
+
+ Set the SELinux
+ security context of the executed
+ process. If set, this will override
+ the automated domain
+ transition. However, the policy still
+ needs to autorize the transition. This
+ directive is ignored if SELinux is
+ disabled. If prefixed by
+ -, all errors will
+ be ignored. See
+ setexeccon3
+ for details.
+
+
IgnoreSIGPIPE=