Преглед изворни кода

Merge remote-tracking branch 'candrews/issue13805'

Nick Mathewson пре 9 година
родитељ
комит
c98e075ebc
1 измењених фајлова са 6 додато и 6 уклоњено
  1. 6 6
      contrib/dist/tor.service.in

+ 6 - 6
contrib/dist/tor.service.in

@@ -16,13 +16,13 @@ LimitNOFILE = 32768
 
 # Hardening
 PrivateTmp = yes
-DeviceAllow = /dev/null rw
-DeviceAllow = /dev/urandom r
-InaccessibleDirectories = /home
+PrivateDevices = yes
+ProtectHome = yes
+ProtectSystem = full
 ReadOnlyDirectories = /
-ReadWriteDirectories = @LOCALSTATEDIR@/lib/tor
-ReadWriteDirectories = @LOCALSTATEDIR@/log/tor
-ReadWriteDirectories = @LOCALSTATEDIR@/run/tor
+ReadWriteDirectories = -@LOCALSTATEDIR@/lib/tor
+ReadWriteDirectories = -@LOCALSTATEDIR@/log/tor
+ReadWriteDirectories = -@LOCALSTATEDIR@/run/tor
 NoNewPrivileges = yes
 
 [Install]