matrix.grapheneos.org/systemd/system/matterbridge.service.d/hardening.conf

9 lines
177 B
Plaintext
Raw Normal View History

2022-08-09 06:18:21 -04:00
[Service]
# use a persistent user so that nftables can use it for skuid rules
DynamicUser=false
MemoryDenyWriteExecute=true
RemoveIPC=true
ProcSubset=pid
ProtectProc=invisible