daemon: Harden systemd service

Signed-off-by: Topi Miettinen <toiwoton@gmail.com>
This commit is contained in:
Topi Miettinen 2019-04-10 14:44:28 +03:00 committed by Tanu Kaskinen
parent 4e08c14cc3
commit 279b99e101

View file

@ -17,10 +17,17 @@ Requires=pulseaudio.socket
ConditionUser=!root ConditionUser=!root
[Service] [Service]
ExecStart=@PA_BINARY@ --daemonize=no
LockPersonality=yes
MemoryDenyWriteExecute=yes
NoNewPrivileges=yes
Restart=on-failure
RestrictNamespaces=yes
SystemCallArchitectures=native
SystemCallFilter=@system-service
# Note that notify will only work if --daemonize=no # Note that notify will only work if --daemonize=no
Type=notify Type=notify
ExecStart=@PA_BINARY@ --daemonize=no UMask=0077
Restart=on-failure
[Install] [Install]
Also=pulseaudio.socket Also=pulseaudio.socket