diff options
author | Mark Felder <feld@FreeBSD.org> | 2020-10-23 15:32:32 -0500 |
---|---|---|
committer | Mark Felder <feld@FreeBSD.org> | 2020-10-23 15:32:32 -0500 |
commit | e7b0840b88838f9e14bd2b09060d89c4a656966c (patch) | |
tree | 5ca4825b7120dbcddf9457db320990b2f5497d43 | |
parent | cb3ee4d543861e65a1de974c3920fdecdcf6a6a7 (diff) | |
download | pleroma-e7b0840b88838f9e14bd2b09060d89c4a656966c.tar.gz |
NoNewPrivileges breaks ability to send email via sendmail because it restricts ability to run setuid/setgid binaries
-rw-r--r-- | installation/pleroma.service | 2 |
1 files changed, 0 insertions, 2 deletions
diff --git a/installation/pleroma.service b/installation/pleroma.service index ee00a3b7a..63e83ed6e 100644 --- a/installation/pleroma.service +++ b/installation/pleroma.service @@ -31,8 +31,6 @@ ProtectHome=true ProtectSystem=full ; Sets up a new /dev mount for the process and only adds API pseudo devices like /dev/null, /dev/zero or /dev/random but not physical devices. Disabled by default because it may not work on devices like the Raspberry Pi. PrivateDevices=false -; Ensures that the service process and all its children can never gain new privileges through execve(). -NoNewPrivileges=true ; Drops the sysadmin capability from the daemon. CapabilityBoundingSet=~CAP_SYS_ADMIN |