This commit is contained in:
JustArchi 2022-10-12 13:49:19 +02:00
parent 6644ec18de
commit 96296028c1
No known key found for this signature in database
GPG key ID: 6B138B4C64555AEA
3 changed files with 15 additions and 3 deletions

View file

@ -33,12 +33,16 @@ RestrictAddressFamilies=AF_INET AF_INET6
RestrictNamespaces=yes
RestrictRealtime=yes
RestrictSUIDSGID=yes
SecureBits=noroot-locked
SystemCallArchitectures=native
SystemCallFilter=@system-service
SystemCallFilter=~@privileged
UMask=0077
# TODO: Requires systemd v247+ due to https://github.com/systemd/systemd/issues/16666
# Since we don't want to enforce OS upgrade for everybody just yet, it's commented out for now
# We'll likely enforce it when .NET switches to Debian 11+ requirement
#SecureBits=noroot-locked
[Unit]
After=network.target
Description=ArchiSteamFarm Service (on %I)

View file

@ -33,12 +33,16 @@ RestrictAddressFamilies=AF_INET AF_INET6
RestrictNamespaces=yes
RestrictRealtime=yes
RestrictSUIDSGID=yes
SecureBits=noroot-locked
SystemCallArchitectures=native
SystemCallFilter=@system-service
SystemCallFilter=~@privileged
UMask=0077
# TODO: Requires systemd v247+ due to https://github.com/systemd/systemd/issues/16666
# Since we don't want to enforce OS upgrade for everybody just yet, it's commented out for now
# We'll likely enforce it when .NET switches to Debian 11+ requirement
#SecureBits=noroot-locked
[Unit]
After=network.target
Description=ArchiSteamFarm Service (on %I)

View file

@ -33,12 +33,16 @@ RestrictAddressFamilies=AF_INET AF_INET6
RestrictNamespaces=yes
RestrictRealtime=yes
RestrictSUIDSGID=yes
SecureBits=noroot-locked
SystemCallArchitectures=native
SystemCallFilter=@system-service
SystemCallFilter=~@privileged
UMask=0077
# TODO: Requires systemd v247+ due to https://github.com/systemd/systemd/issues/16666
# Since we don't want to enforce OS upgrade for everybody just yet, it's commented out for now
# We'll likely enforce it when .NET switches to Debian 11+ requirement
#SecureBits=noroot-locked
[Unit]
After=network.target
Description=ArchiSteamFarm Service (on %I)