Parcourir la source

Merge remote-tracking branch 'intrigeri/bug12939-systemd-no-new-privileges'

Conflicts:
	contrib/dist/tor.service.in
Nick Mathewson il y a 10 ans
Parent
commit
54348201f7
2 fichiers modifiés avec 5 ajouts et 0 suppressions
  1. 4 0
      changes/bug12939-systemd-no-new-privileges
  2. 1 0
      contrib/dist/tor.service.in

+ 4 - 0
changes/bug12939-systemd-no-new-privileges

@@ -0,0 +1,4 @@
+  o Distribution:
+    - systemd unit file: ensures that the process and all its children
+      can never gain new privileges.
+      Patch by intrigeri; resolves ticket 12939.

+ 1 - 0
contrib/dist/tor.service.in

@@ -22,6 +22,7 @@ InaccessibleDirectories = /home
 ReadOnlyDirectories = /
 ReadWriteDirectories = @LOCALSTATEDIR@/lib/tor
 ReadWriteDirectories = @LOCALSTATEDIR@/log/tor
+NoNewPrivileges = yes
 
 [Install]
 WantedBy = multi-user.target