浏览代码

Add ProtectSystem = full

See 13805
Craig Andrews 9 年之前
父节点
当前提交
5bdf12ca8a
共有 1 个文件被更改,包括 1 次插入0 次删除
  1. 1 0
      contrib/dist/tor.service.in

+ 1 - 0
contrib/dist/tor.service.in

@@ -18,6 +18,7 @@ LimitNOFILE = 32768
 PrivateTmp = yes
 PrivateDevices = yes
 ProtectHome = yes
+ProtectSystem = full
 ReadOnlyDirectories = /
 ReadWriteDirectories = -@LOCALSTATEDIR@/lib/tor
 ReadWriteDirectories = -@LOCALSTATEDIR@/log/tor