Skip to content

Commit

Permalink
Updated haveged.service to allow chroot when included in initramfs
Browse files Browse the repository at this point in the history
  • Loading branch information
Jirka Hladky committed Jan 2, 2021
1 parent 13925fb commit 4da3080
Showing 1 changed file with 3 additions and 2 deletions.
5 changes: 3 additions & 2 deletions contrib/Fedora/haveged.service
Original file line number Diff line number Diff line change
Expand Up @@ -11,11 +11,12 @@ Restart=always
SuccessExitStatus=137 143

SecureBits=noroot-locked
CapabilityBoundingSet=CAP_SYS_ADMIN
CapabilityBoundingSet=CAP_SYS_ADMIN CAP_SYS_CHROOT
# We can *not* set PrivateTmp=true as it can cause an ordering cycle.
PrivateTmp=false
PrivateDevices=true
PrivateNetwork=true
# We can *not* set PrivateNetwork=true to allow command mode (chroot when included in initramfs)
#PrivateNetwork=true
ProtectSystem=full
ProtectHome=true
ProtectHostname=true
Expand Down

0 comments on commit 4da3080

Please sign in to comment.