Open marek22k opened 1 year ago
Ping on maintainer: @kpcyrd @cjdelisle
Most of this is unnecessary because cjdns uses SECCOMP to drop privileges after startup; don't rely blindly on what systemd-analyze tells you.
Regardless, have you tried sending a PR to add these restrictions to the systemd unit?
The Systemd unit at https://github.com/cjdelisle/cjdns/blob/master/contrib/systemd/cjdns.service seems to be quite insecure. Is it possible to improve this?