From c4e789e2dfb7899c8738b73bfe8bd61d4fa1856a Mon Sep 17 00:00:00 2001 From: ginuerzh Date: Mon, 21 Sep 2026 21:03:43 +0800 Subject: [PATCH] fix(release): pin capability bounding set in gost.service CapabilityBoundingSet= was dropped when CAP_NET_ADMIN was added for TUN, which leaves the bounding set unrestricted. Pin it to the capabilities the unit actually needs. Restore ~@privileged as well: TUN uses ioctl(TUNSETIFF) and netlink, neither of which is in that group. --- gost.service | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/gost.service b/gost.service index 92aefac..e2b2f6f 100644 --- a/gost.service +++ b/gost.service @@ -18,6 +18,7 @@ Restart=on-failure RestartSec=1s AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE +CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE PrivateTmp=yes PrivateDevices=no @@ -32,7 +33,7 @@ ProtectClock=yes MemoryDenyWriteExecute=yes NoNewPrivileges=yes -SystemCallFilter=~@mount @debug @cpu-emulation @obsolete +SystemCallFilter=~@privileged @mount @debug @cpu-emulation @obsolete SystemCallErrorNumber=EPERM SystemCallArchitectures=native RestrictNamespaces=yes