Revert some hardening that breaks LXC

For each of these, we should be OK since we run as an unprivileged user
anyways.
This commit is contained in:
Joshua M. Boniface 2021-12-12 16:57:35 -05:00
parent 2c6d6dbbf8
commit 9a2b88cb1f

View File

@ -13,17 +13,17 @@ TimeoutSec = 15
NoNewPrivileges=true NoNewPrivileges=true
SystemCallArchitectures=native SystemCallArchitectures=native
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
RestrictNamespaces=true RestrictNamespaces=false
RestrictRealtime=true RestrictRealtime=true
RestrictSUIDSGID=true RestrictSUIDSGID=true
ProtectClock=true ProtectClock=true
ProtectControlGroups=true ProtectControlGroups=false
ProtectHostname=true ProtectHostname=true
ProtectKernelLogs=true ProtectKernelLogs=false
ProtectKernelModules=true ProtectKernelModules=false
ProtectKernelTunables=true ProtectKernelTunables=false
LockPersonality=true LockPersonality=true
PrivateTmp=true PrivateTmp=false
PrivateDevices=false PrivateDevices=false
PrivateUsers=true PrivateUsers=true
RemoveIPC=true RemoveIPC=true