From: Peter Palfrader Date: Mon, 6 Feb 2017 22:04:41 +0000 (+0100) Subject: Add CAP_DAC_READ_SEARCH to CapabilityBoundingSet for rsync X-Git-Url: https://git.adam-barratt.org.uk/?a=commitdiff_plain;h=ecbf3a6d2af0b738e683cf0840898a7dc53dd8e5;p=mirror%2Fdsa-puppet.git Add CAP_DAC_READ_SEARCH to CapabilityBoundingSet for rsync --- diff --git a/modules/rsync/templates/systemd-rsyncd.service.erb b/modules/rsync/templates/systemd-rsyncd.service.erb index 2a21d6508..5ecc685a7 100644 --- a/modules/rsync/templates/systemd-rsyncd.service.erb +++ b/modules/rsync/templates/systemd-rsyncd.service.erb @@ -5,7 +5,7 @@ Description=rsync daemon <%= @name %> ExecStart=-/usr/bin/rsync --daemon --config=<%= @fname_real_rsync %> StandardInput=socket StandardError=journal -CapabilityBoundingSet=CAP_SYS_CHROOT CAP_SETUID CAP_SETGID +CapabilityBoundingSet=CAP_SYS_CHROOT CAP_SETUID CAP_SETGID CAP_DAC_READ_SEARCH PrivateDevices=true PrivateNetwork=true ProtectHome=read-only