mirror of
https://github.com/NLnetLabs/unbound.git
synced 2025-12-24 00:29:58 -05:00
unbound.service.in: allow CAP_NET_ADMIN
Allowing CAP_NET_ADMIN is necessary for SO_SNDBUFFORCE and SO_RCVBUFFORCE calls.
This commit is contained in:
parent
e471e15774
commit
fa6340cfa5
1 changed files with 1 additions and 1 deletions
|
|
@ -59,7 +59,7 @@ ExecReload=+/bin/kill -HUP $MAINPID
|
||||||
ExecStart=@UNBOUND_SBIN_DIR@/unbound -d -p
|
ExecStart=@UNBOUND_SBIN_DIR@/unbound -d -p
|
||||||
NotifyAccess=main
|
NotifyAccess=main
|
||||||
Type=notify
|
Type=notify
|
||||||
CapabilityBoundingSet=CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_SYS_RESOURCE CAP_NET_RAW
|
CapabilityBoundingSet=CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_SYS_RESOURCE CAP_NET_RAW CAP_NET_ADMIN
|
||||||
MemoryDenyWriteExecute=true
|
MemoryDenyWriteExecute=true
|
||||||
NoNewPrivileges=true
|
NoNewPrivileges=true
|
||||||
PrivateDevices=true
|
PrivateDevices=true
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue