Skip to content

Commit

Permalink
wtmpdbd.service: secure more
Browse files Browse the repository at this point in the history
  • Loading branch information
thkukuk committed Jan 17, 2025
1 parent e4e22fc commit a9b48cf
Showing 1 changed file with 4 additions and 2 deletions.
6 changes: 4 additions & 2 deletions units/wtmpdbd.service
Original file line number Diff line number Diff line change
Expand Up @@ -7,21 +7,23 @@ Type=notify
Environment="WTMPDBD_OPTS="
EnvironmentFile=-/etc/default/wtmpdbd
ExecStart=/usr/libexec/wtmpdbd -s $WTMPDBD_OPTS
#DeviceAllow=/dev/vsock r
IPAddressDeny=any
LockPersonality=yes
MemoryDenyWriteExecute=yes
NoNewPrivileges=yes
PrivateDevices=yes
PrivateNetwork=yes
PrivateTmp=yes
ProtectClock=yes
ProtectControlGroups=yes
ProtectHome=yes
ProtectKernelLogs=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
ProtectProc=invisible
ProtectSystem=strict
ReadWritePaths=/etc /run/wtmpdb /var/lib/wtmpdb
RestrictRealtime=true
ReadWritePaths=/run/wtmpdb /var/lib/wtmpdb
RestrictAddressFamilies=AF_UNIX
RestrictNamespaces=yes
RestrictRealtime=yes
Expand Down

0 comments on commit a9b48cf

Please sign in to comment.