diff options
author | Iago López Galeiras <iagol@microsoft.com> | 2023-09-20 11:40:47 +0200 |
---|---|---|
committer | Iago López Galeiras <iagol@microsoft.com> | 2023-11-07 11:31:53 +0100 |
commit | e720cebf7cce7a6fe7d160ac968c2dc51a5c613a (patch) | |
tree | 1ad0a6d4e610d51781994511e5a949c736b2a94e /man | |
parent | core: allow using seccomp without no_new_privs when unprivileged (diff) | |
download | systemd-e720cebf7cce7a6fe7d160ac968c2dc51a5c613a.tar.xz systemd-e720cebf7cce7a6fe7d160ac968c2dc51a5c613a.zip |
test-execute: add no_new_privs tests for SystemCallFilter
When starting a service with a non-root user and a SystemCallFilter and
other settings (like ProtectClock), the no_new_privs flag should not be set.
Also, test that CapabilityBoundingSet behaves correctly, since we need
to preserve some capabilities to do the seccomp filter and restore the
ones set by the service before executing.
Diffstat (limited to 'man')
0 files changed, 0 insertions, 0 deletions