projects
/
mirror
/
dsa-puppet.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
| inline |
side by side
Allow rsyncd to access /home read-only
[mirror/dsa-puppet.git]
/
modules
/
rsync
/
templates
/
systemd-rsyncd.service.erb
diff --git
a/modules/rsync/templates/systemd-rsyncd.service.erb
b/modules/rsync/templates/systemd-rsyncd.service.erb
index
7a5b828
..
2a21d65
100644
(file)
--- a/
modules/rsync/templates/systemd-rsyncd.service.erb
+++ b/
modules/rsync/templates/systemd-rsyncd.service.erb
@@
-8,5
+8,5
@@
StandardError=journal
CapabilityBoundingSet=CAP_SYS_CHROOT CAP_SETUID CAP_SETGID
PrivateDevices=true
PrivateNetwork=true
-ProtectHome=
true
+ProtectHome=
read-only
ProtectSystem=full