X-Git-Url: https://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?p=elogind.git;a=blobdiff_plain;f=units%2Fsystemd-timesyncd.service.in;h=39edafc8d295d7b92536002144cdeac4f5dcb899;hp=ec2871455e88fddf5672e0e1efe9cf4d76fcc246;hb=66f311206e908a5b6f21e66fad73e1e5ea3e31d6;hpb=ece6e766cf89c8ec82ad135969dedf16cd7c1ee8 diff --git a/units/systemd-timesyncd.service.in b/units/systemd-timesyncd.service.in index ec2871455..39edafc8d 100644 --- a/units/systemd-timesyncd.service.in +++ b/units/systemd-timesyncd.service.in @@ -9,20 +9,24 @@ Description=Network Time Synchronization Documentation=man:systemd-timesyncd.service(8) ConditionCapability=CAP_SYS_TIME -DefaultDependencies=off +ConditionVirtualization=no +DefaultDependencies=no RequiresMountsFor=/var/lib/systemd/clock -After=systemd-remount-fs.service -Before=sysinit.target shutdown.target +After=systemd-remount-fs.service systemd-tmpfiles-setup.service systemd-sysusers.service +Before=time-sync.target sysinit.target shutdown.target Conflicts=shutdown.target +Wants=time-sync.target [Service] Type=notify Restart=always RestartSec=0 ExecStart=@rootlibexecdir@/systemd-timesyncd -CapabilityBoundingSet=CAP_SYS_TIME CAP_SETUID CAP_SETGID CAP_SETPCAP CAP_CHOWN CAP_DAC_OVERRIDE +CapabilityBoundingSet=CAP_SYS_TIME CAP_SETUID CAP_SETGID CAP_SETPCAP CAP_CHOWN CAP_DAC_OVERRIDE CAP_FOWNER PrivateTmp=yes PrivateDevices=yes +ProtectSystem=full +ProtectHome=yes WatchdogSec=1min [Install]