mirror of
https://github.com/go-gost/gost.git
synced 2026-10-09 12:35:45 +00:00
fix(release): pin capability bounding set in gost.service
CapabilityBoundingSet= was dropped when CAP_NET_ADMIN was added for TUN, which leaves the bounding set unrestricted. Pin it to the capabilities the unit actually needs. Restore ~@privileged as well: TUN uses ioctl(TUNSETIFF) and netlink, neither of which is in that group.
This commit is contained in:
+2
-1
@@ -18,6 +18,7 @@ Restart=on-failure
|
|||||||
RestartSec=1s
|
RestartSec=1s
|
||||||
|
|
||||||
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
|
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
|
||||||
|
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
|
||||||
|
|
||||||
PrivateTmp=yes
|
PrivateTmp=yes
|
||||||
PrivateDevices=no
|
PrivateDevices=no
|
||||||
@@ -32,7 +33,7 @@ ProtectClock=yes
|
|||||||
MemoryDenyWriteExecute=yes
|
MemoryDenyWriteExecute=yes
|
||||||
NoNewPrivileges=yes
|
NoNewPrivileges=yes
|
||||||
|
|
||||||
SystemCallFilter=~@mount @debug @cpu-emulation @obsolete
|
SystemCallFilter=~@privileged @mount @debug @cpu-emulation @obsolete
|
||||||
SystemCallErrorNumber=EPERM
|
SystemCallErrorNumber=EPERM
|
||||||
SystemCallArchitectures=native
|
SystemCallArchitectures=native
|
||||||
RestrictNamespaces=yes
|
RestrictNamespaces=yes
|
||||||
|
|||||||
Reference in New Issue
Block a user