Skip to content
Snippets Groups Projects

hardening: use default ptrace scope on buildservers

Merged Evangelos Foutras requested to merge remove-ptrace-hardening-from-buildservers into master
1 file
+ 1
0
Compare changes
  • Side-by-side
  • Inline
@@ -7,6 +7,7 @@
- name: set ptrace scope, restrict ptrace to CAP_SYS_PTRACE
copy: src=50-ptrace-restrict.conf dest=/etc/sysctl.d/50-ptrace-restrict.conf owner=root group=root mode=0644
when: "'buildservers' not in group_names"
notify:
- apply sysctl settings
Loading