aboutsummaryrefslogtreecommitdiff
path: root/installation
diff options
context:
space:
mode:
authorshibayashi <shibayashi@cypherpunk.observer>2018-10-25 00:57:47 +0200
committershibayashi <shibayashi@cypherpunk.observer>2018-10-25 00:57:47 +0200
commit043cb7138e3e970d0e50f3f5a9be5efb385bbc92 (patch)
treee47e333682574480d399f3f1cb3ddf833819ac46 /installation
parent0a58428de6096f3222dd30d1a1f186150c25f4f2 (diff)
downloadpleroma-043cb7138e3e970d0e50f3f5a9be5efb385bbc92.tar.gz
Add a little bit more detail in the comments.
Diffstat (limited to 'installation')
-rw-r--r--installation/pleroma.service4
1 files changed, 2 insertions, 2 deletions
diff --git a/installation/pleroma.service b/installation/pleroma.service
index e410764f3..84747d952 100644
--- a/installation/pleroma.service
+++ b/installation/pleroma.service
@@ -14,11 +14,11 @@ Restart=on-failure
; Some security directives.
; Use private /tmp and /var/tmp folders inside a new file system namespace, which are discarded after the process stops.
PrivateTmp=true
-; This makes /usr, /boot, /etc read-only.
+; Mount /usr, /boot, and /etc as read-only for processes invoked by this service.
ProtectSystem=full
; Sets up a new /dev mount for the process and only adds API pseudo devices like /dev/null, /dev/zero or /dev/random but not physical devices. Disabled by default because it may not work on devices like the Raspberry Pi.
PrivateDevices=false
-; Ensures that the service process and all its children can never gain new privileges through execve()
+; Ensures that the service process and all its children can never gain new privileges through execve().
NoNewPrivileges=true
[Install]