Verified Commit 53f0a372 authored by Frederik “Freso” S. Olesen's avatar Frederik “Freso” S. Olesen Committed by Alexander Epaneshnikov
Browse files

paccache.service.in: Restrict all (network) address families



RestrictAddressFamilies used to not have an option to restrict all
address families, but systemd 249 introduced a special value "none"
exactly for this purpose.
Signed-off-by: Frederik “Freso” S. Olesen's avatarFrederik “Freso” S. Olesen <freso.dk@gmail.com>
parent 35934ef3
......@@ -28,7 +28,7 @@ ProtectKernelTunables=yes
ProtectKernelModules=yes
ProtectKernelLogs=yes
ProtectControlGroups=yes
RestrictAddressFamilies=AF_UNIX
RestrictAddressFamilies=none
RestrictNamespaces=yes
LockPersonality=yes
MemoryDenyWriteExecute=yes
......
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment