mirror of
https://github.com/knadh/listmonk.git
synced 2025-12-05 16:00:03 +01:00
Enable extra system calls in systemd service (#1309)
This commit is contained in:
@@ -35,7 +35,7 @@ SystemCallArchitectures=native
|
|||||||
# Only enable a reasonable set of system calls.
|
# Only enable a reasonable set of system calls.
|
||||||
# see: https://www.freedesktop.org/software/systemd/man/systemd.exec.html#SystemCallFilter=
|
# see: https://www.freedesktop.org/software/systemd/man/systemd.exec.html#SystemCallFilter=
|
||||||
SystemCallFilter=@system-service
|
SystemCallFilter=@system-service
|
||||||
SystemCallFilter=~@privileged @resources
|
SystemCallFilter=~@privileged
|
||||||
# ProtectSystem=strict, which is implied by DynamicUser=True, already disabled write calls
|
# ProtectSystem=strict, which is implied by DynamicUser=True, already disabled write calls
|
||||||
# to the entire filesystem hierarchy, leaving only /dev/, /proc/, and /sys/ writable.
|
# to the entire filesystem hierarchy, leaving only /dev/, /proc/, and /sys/ writable.
|
||||||
# listmonk doesn’t need access to those so might as well disable them.
|
# listmonk doesn’t need access to those so might as well disable them.
|
||||||
|
|||||||
Reference in New Issue
Block a user