mirror of
https://github.com/tailscale/tailscale.git
synced 2025-02-22 12:58:37 +00:00
cmd/tailscaled/tailscaled.service: revert recent hardening for now
It broke Debian Stretch. We'll try again later. Updates #1245 Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com> (cherry picked from commit 2889fabaefc50040507ead652d6d2b212f476c2b)
This commit is contained in:
parent
dde7ba4ecf
commit
bb0ef32dd2
@ -20,24 +20,5 @@ CacheDirectory=tailscale
|
|||||||
CacheDirectoryMode=0750
|
CacheDirectoryMode=0750
|
||||||
Type=notify
|
Type=notify
|
||||||
|
|
||||||
DeviceAllow=/dev/net/tun
|
|
||||||
DeviceAllow=/dev/null
|
|
||||||
DeviceAllow=/dev/random
|
|
||||||
DeviceAllow=/dev/urandom
|
|
||||||
DevicePolicy=strict
|
|
||||||
LockPersonality=true
|
|
||||||
MemoryDenyWriteExecute=true
|
|
||||||
PrivateTmp=true
|
|
||||||
ProtectClock=true
|
|
||||||
ProtectControlGroups=true
|
|
||||||
ProtectHome=true
|
|
||||||
ProtectKernelTunables=true
|
|
||||||
ProtectSystem=strict
|
|
||||||
ReadWritePaths=/etc/
|
|
||||||
ReadWritePaths=/run/
|
|
||||||
ReadWritePaths=/var/run/
|
|
||||||
RestrictSUIDSGID=true
|
|
||||||
SystemCallArchitectures=native
|
|
||||||
|
|
||||||
[Install]
|
[Install]
|
||||||
WantedBy=multi-user.target
|
WantedBy=multi-user.target
|
||||||
|
Loading…
x
Reference in New Issue
Block a user