diff options
author | Lennart Poettering <lennart@poettering.net> | 2016-08-22 18:43:59 +0200 |
---|---|---|
committer | Djalal Harouni <tixxdz@opendz.org> | 2016-09-25 10:18:48 +0200 |
commit | 59eeb84ba65483c5543d1bc840c2ac75642ef638 (patch) | |
tree | 2195a40c7daf3575a8a7500bc8a82412056688ab /src/core/execute.h | |
parent | 72246c2a654ead7f7ee6e7799161e2e46dc0b84b (diff) |
core: add two new service settings ProtectKernelTunables= and ProtectControlGroups=
If enabled, these will block write access to /sys, /proc/sys and
/proc/sys/fs/cgroup.
Diffstat (limited to 'src/core/execute.h')
-rw-r--r-- | src/core/execute.h | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/src/core/execute.h b/src/core/execute.h index 6082c42aba..449180c903 100644 --- a/src/core/execute.h +++ b/src/core/execute.h @@ -174,6 +174,8 @@ struct ExecContext { bool private_users; ProtectSystem protect_system; ProtectHome protect_home; + bool protect_kernel_tunables; + bool protect_control_groups; bool no_new_privileges; |