systemd: enable basic hardening
This ensures that systemd will not allow us to modify /home, /root and /run/user which we shouldn't be doing anyway. See https://www.freedesktop.org/software/systemd/man/systemd.exec.html for details. It should also should silence corresponding lintian warning. Related: OS#4107 Change-Id: Ida5f13bdb9e5bd956c440a381d94eecc18f0b2efchanges/79/29379/2
parent
023c6524a2
commit
00aea9e0d9
|
@ -9,6 +9,7 @@ StateDirectory=osmocom
|
|||
WorkingDirectory=%S/osmocom
|
||||
ExecStart=/usr/bin/osmo-hlr -c /etc/osmocom/osmo-hlr.cfg -l /var/lib/osmocom/hlr.db
|
||||
RestartSec=2
|
||||
ProtectHome=true
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
|
|
Loading…
Reference in New Issue