Files
gost/gost.service
T
ginuerzh c4e789e2df fix(release): pin capability bounding set in gost.service
CapabilityBoundingSet= was dropped when CAP_NET_ADMIN was added for TUN,
which leaves the bounding set unrestricted. Pin it to the capabilities the
unit actually needs. Restore ~@privileged as well: TUN uses ioctl(TUNSETIFF)
and netlink, neither of which is in that group.
2026-09-21 21:03:43 +08:00

45 lines
987 B
Desktop File

[Unit]
Description=GO Simple Tunnel
Documentation=https://gost.run/
After=network-online.target nss-lookup.target
ConditionPathExists=/etc/gost/gost.yml
[Service]
Type=simple
WorkingDirectory=/run/gost
ExecStart=/usr/bin/gost -C /etc/gost/gost.yml
ExecReload=/bin/kill -SIGHUP $MAINPID
User=nobody
RuntimeDirectory=gost
LogsDirectory=gost
TimeoutStopSec=5s
Restart=on-failure
RestartSec=1s
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
PrivateTmp=yes
PrivateDevices=no
ProtectSystem=full
ProtectHostname=yes
ProtectHome=yes
ProtectKernelTunables=yes
ProtectKernelLogs=yes
ProtectKernelModules=yes
ProtectControlGroups=yes
ProtectClock=yes
MemoryDenyWriteExecute=yes
NoNewPrivileges=yes
SystemCallFilter=~@privileged @mount @debug @cpu-emulation @obsolete
SystemCallErrorNumber=EPERM
SystemCallArchitectures=native
RestrictNamespaces=yes
RestrictSUIDSGID=yes
LockPersonality=yes
[Install]
WantedBy=multi-user.target