Browse Source

Add AmbientCapabilities for all.

pull/2182/head
edsgerlin 6 years ago
parent
commit
0496416387
5 changed files with 5 additions and 0 deletions
  1. 1
      debian/shadowsocks-libev-local@.service
  2. 1
      debian/shadowsocks-libev-redir@.service
  3. 1
      debian/shadowsocks-libev-server@.service
  4. 1
      debian/shadowsocks-libev-tunnel@.service
  5. 1
      debian/shadowsocks-libev.service

1
debian/shadowsocks-libev-local@.service

@ -17,6 +17,7 @@ After=network.target
[Service]
Type=simple
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
AmbientCapabilities=CAP_NET_BIND_SERVICE
ExecStart=/usr/bin/ss-local -c /etc/shadowsocks-libev/%i.json
[Install]

1
debian/shadowsocks-libev-redir@.service

@ -17,6 +17,7 @@ After=network.target
[Service]
Type=simple
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
ExecStart=/usr/bin/ss-redir -c /etc/shadowsocks-libev/%i.json
[Install]

1
debian/shadowsocks-libev-server@.service

@ -17,6 +17,7 @@ After=network.target
[Service]
Type=simple
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
AmbientCapabilities=CAP_NET_BIND_SERVICE
ExecStart=/usr/bin/ss-server -c /etc/shadowsocks-libev/%i.json
[Install]

1
debian/shadowsocks-libev-tunnel@.service

@ -17,6 +17,7 @@ After=network.target
[Service]
Type=simple
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
AmbientCapabilities=CAP_NET_BIND_SERVICE
ExecStart=/usr/bin/ss-tunnel -c /etc/shadowsocks-libev/%i.json
[Install]

1
debian/shadowsocks-libev.service

@ -16,6 +16,7 @@ After=network.target
[Service]
Type=simple
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
AmbientCapabilities=CAP_NET_BIND_SERVICE
EnvironmentFile=/etc/default/shadowsocks-libev
User=nobody
Group=nogroup

Loading…
Cancel
Save