Skip to content

Commit

Permalink
Update Systemd security settings
Browse files Browse the repository at this point in the history
  • Loading branch information
Rahul Sundaram committed Mar 7, 2024
1 parent f1e4ad6 commit 7eade14
Showing 1 changed file with 21 additions and 0 deletions.
21 changes: 21 additions & 0 deletions data/packagekit.service.in
Original file line number Diff line number Diff line change
Expand Up @@ -11,3 +11,24 @@ Type=dbus
BusName=org.freedesktop.PackageKit
User=@PACKAGEKIT_USER@
ExecStart=@libexecdir@/packagekitd
DevicePolicy=closed
KeyringMode=private
LockPersonality=yes
MemoryDenyWriteExecute=yes
NoNewPrivileges=no
PrivateDevices=yes
PrivateTmp=true
ProtectClock=yes
ProtectControlGroups=yes
ProtectHome=yes
ProtectHostname=yes
ProtectKernelLogs=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
ProtectProc=invisible
ProtectSystem=no
RemoveIPC=yes
RestrictNamespaces=yes
RestrictRealtime=yes
RestrictSUIDSGID=yes
SystemCallArchitectures=native

0 comments on commit 7eade14

Please sign in to comment.