Pārlūkot izejas kodu

Use PrivateDevices instead of DeviceAllow

See 13805
Craig Andrews 9 gadi atpakaļ
vecāks
revīzija
1ac3b74405
1 mainītis faili ar 1 papildinājumiem un 2 dzēšanām
  1. 1 2
      contrib/dist/tor.service.in

+ 1 - 2
contrib/dist/tor.service.in

@@ -16,8 +16,7 @@ LimitNOFILE = 32768
 
 # Hardening
 PrivateTmp = yes
-DeviceAllow = /dev/null rw
-DeviceAllow = /dev/urandom r
+PrivateDevices = yes
 InaccessibleDirectories = /home
 ReadOnlyDirectories = /
 ReadWriteDirectories = @LOCALSTATEDIR@/lib/tor