diff options
| author | Djalal Harouni <tixxdz@opendz.org> | 2016-10-12 13:31:21 +0200 | 
|---|---|---|
| committer | Djalal Harouni <tixxdz@opendz.org> | 2016-10-12 13:31:21 +0200 | 
| commit | 502d704e5ed2d288069471f4e3611115cde107d6 (patch) | |
| tree | 4f477c49d4ce8b979479735bcc4f4043b2df111b /src/nspawn/nspawn-stub-pid1.c | |
| parent | 18e51a022c632344c4a48ba6ccb3475fad2a2c3b (diff) | |
core:sandbox: Add ProtectKernelModules= option
This is useful to turn off explicit module load and unload operations on modular
kernels. This option removes CAP_SYS_MODULE from the capability bounding set for
the unit, and installs a system call filter to block module system calls.
This option will not prevent the kernel from loading modules using the module
auto-load feature which is a system wide operation.
Diffstat (limited to 'src/nspawn/nspawn-stub-pid1.c')
0 files changed, 0 insertions, 0 deletions
