fix(release): pin capability bounding set in gost.service

CapabilityBoundingSet= was dropped when CAP_NET_ADMIN was added for TUN,
which leaves the bounding set unrestricted. Pin it to the capabilities the
unit actually needs. Restore ~@privileged as well: TUN uses ioctl(TUNSETIFF)
and netlink, neither of which is in that group.
This commit is contained in:
ginuerzh
2026-09-21 21:03:43 +08:00
parent 2a6ba4df85
commit c4e789e2df
+2 -1
View File
@@ -18,6 +18,7 @@ Restart=on-failure
RestartSec=1s
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
PrivateTmp=yes
PrivateDevices=no
@@ -32,7 +33,7 @@ ProtectClock=yes
MemoryDenyWriteExecute=yes
NoNewPrivileges=yes
SystemCallFilter=~@mount @debug @cpu-emulation @obsolete
SystemCallFilter=~@privileged @mount @debug @cpu-emulation @obsolete
SystemCallErrorNumber=EPERM
SystemCallArchitectures=native
RestrictNamespaces=yes