matrix.grapheneos.org/systemd/system/matterbridge.service.d/hardening.conf
2022-08-09 07:42:11 -04:00

9 lines
177 B
Plaintext

[Service]
# use a persistent user so that nftables can use it for skuid rules
DynamicUser=false
MemoryDenyWriteExecute=true
RemoveIPC=true
ProcSubset=pid
ProtectProc=invisible