summaryrefslogtreecommitdiffstats
path: root/man
diff options
context:
space:
mode:
authorIago López Galeiras <iagol@microsoft.com>2023-09-20 11:40:47 +0200
committerIago López Galeiras <iagol@microsoft.com>2023-11-07 11:31:53 +0100
commite720cebf7cce7a6fe7d160ac968c2dc51a5c613a (patch)
tree1ad0a6d4e610d51781994511e5a949c736b2a94e /man
parentcore: allow using seccomp without no_new_privs when unprivileged (diff)
downloadsystemd-e720cebf7cce7a6fe7d160ac968c2dc51a5c613a.tar.xz
systemd-e720cebf7cce7a6fe7d160ac968c2dc51a5c613a.zip
test-execute: add no_new_privs tests for SystemCallFilter
When starting a service with a non-root user and a SystemCallFilter and other settings (like ProtectClock), the no_new_privs flag should not be set. Also, test that CapabilityBoundingSet behaves correctly, since we need to preserve some capabilities to do the seccomp filter and restore the ones set by the service before executing.
Diffstat (limited to 'man')
0 files changed, 0 insertions, 0 deletions