From 5833143708733a3fc9e6935922bf11d7d27cb768 Mon Sep 17 00:00:00 2001 From: Christian Hesse Date: Tue, 30 Jun 2015 19:12:20 +0200 Subject: man: ProtectHome= protects /root as well --- man/systemd.exec.xml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) (limited to 'man/systemd.exec.xml') diff --git a/man/systemd.exec.xml b/man/systemd.exec.xml index 64877720bc..45a4422dc3 100644 --- a/man/systemd.exec.xml +++ b/man/systemd.exec.xml @@ -858,9 +858,10 @@ Takes a boolean argument or read-only. If true, the directories - /home and /run/user + /home, /root and + /run/user are made inaccessible and empty for processes invoked by this - unit. If set to read-only, the two + unit. If set to read-only, the three directories are made read-only instead. It is recommended to enable this setting for all long-running services (in particular network-facing ones), to ensure they cannot get -- cgit v1.2.3-54-g00ecf