mirror of
https://github.com/systemd/systemd
synced 2025-09-26 15:24:44 +02:00
Compare commits
2 Commits
35e7a62ca3
...
9e36b885b8
Author | SHA1 | Date | |
---|---|---|---|
![]() |
9e36b885b8 | ||
![]() |
84f9a68060 |
@ -22,7 +22,7 @@
|
|||||||
* PID1 because 16MB of free space is required. */
|
* PID1 because 16MB of free space is required. */
|
||||||
#define TMPFS_LIMITS_RUN ",size=20%,nr_inodes=800k"
|
#define TMPFS_LIMITS_RUN ",size=20%,nr_inodes=800k"
|
||||||
|
|
||||||
/* The limit used for various nested tmpfs mounts, in paricular for guests started by systemd-nspawn.
|
/* The limit used for various nested tmpfs mounts, in particular for guests started by systemd-nspawn.
|
||||||
* 10% of RAM (using 16GB of RAM as a baseline) translates to 400k inodes (assuming 4k each) and 25%
|
* 10% of RAM (using 16GB of RAM as a baseline) translates to 400k inodes (assuming 4k each) and 25%
|
||||||
* translates to 1M inodes.
|
* translates to 1M inodes.
|
||||||
* (On the host, /tmp is configured through a .mount unit file.) */
|
* (On the host, /tmp is configured through a .mount unit file.) */
|
||||||
|
@ -24,6 +24,7 @@ BusName=org.freedesktop.network1
|
|||||||
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_BROADCAST CAP_NET_RAW
|
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_BROADCAST CAP_NET_RAW
|
||||||
DeviceAllow=char-* rw
|
DeviceAllow=char-* rw
|
||||||
ExecStart=!!@rootlibexecdir@/systemd-networkd
|
ExecStart=!!@rootlibexecdir@/systemd-networkd
|
||||||
|
ExecReload=networkctl reload
|
||||||
LockPersonality=yes
|
LockPersonality=yes
|
||||||
MemoryDenyWriteExecute=yes
|
MemoryDenyWriteExecute=yes
|
||||||
NoNewPrivileges=yes
|
NoNewPrivileges=yes
|
||||||
|
Loading…
x
Reference in New Issue
Block a user