add missing capability CAP_FSETID to mox.service

without it, process cannot create setgid directories.
This commit is contained in:
Mechiel Lukkien 2023-02-27 14:04:20 +01:00
parent f3f2c6f8ea
commit e20677cfd6
No known key found for this signature in database

View file

@ -22,7 +22,7 @@ ReadWritePaths=/home/mox/config /home/mox/data
ProtectKernelTunables=yes
ProtectControlGroups=yes
AmbientCapabilities=
CapabilityBoundingSet=CAP_SETUID CAP_SETGID CAP_NET_BIND_SERVICE CAP_CHOWN
CapabilityBoundingSet=CAP_SETUID CAP_SETGID CAP_NET_BIND_SERVICE CAP_CHOWN CAP_FSETID
NoNewPrivileges=yes
RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX AF_NETLINK
ProtectProc=invisible