mirror of
https://github.com/go-gost/gost.git
synced 2026-10-08 03:55:45 +00:00
fix(release): pin capability bounding set in gost.service
CapabilityBoundingSet= was dropped when CAP_NET_ADMIN was added for TUN, which leaves the bounding set unrestricted. Pin it to the capabilities the unit actually needs. Restore ~@privileged as well: TUN uses ioctl(TUNSETIFF) and netlink, neither of which is in that group.
This commit is contained in:
+2
-1
@@ -18,6 +18,7 @@ Restart=on-failure
|
||||
RestartSec=1s
|
||||
|
||||
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
|
||||
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
|
||||
|
||||
PrivateTmp=yes
|
||||
PrivateDevices=no
|
||||
@@ -32,7 +33,7 @@ ProtectClock=yes
|
||||
MemoryDenyWriteExecute=yes
|
||||
NoNewPrivileges=yes
|
||||
|
||||
SystemCallFilter=~@mount @debug @cpu-emulation @obsolete
|
||||
SystemCallFilter=~@privileged @mount @debug @cpu-emulation @obsolete
|
||||
SystemCallErrorNumber=EPERM
|
||||
SystemCallArchitectures=native
|
||||
RestrictNamespaces=yes
|
||||
|
||||
Reference in New Issue
Block a user