diff options
| author | Michael Biebl <biebl@debian.org> | 2022-01-13 22:30:39 +0100 |
|---|---|---|
| committer | Michael Biebl <biebl@debian.org> | 2022-01-13 22:30:39 +0100 |
| commit | 88c227d90a6b7b388c5c85d72802a0ca8f05ed5c (patch) | |
| tree | 71f32df6617802270e8a78574bd8e1637dc532f4 /data/nm-priv-helper.service.in | |
| parent | e74c568b07b50b97873fb4ee1d776dedefbd54d6 (diff) | |
New upstream version 1.34.0 upstream/1.34.0
Diffstat (limited to 'data/nm-priv-helper.service.in')
| -rw-r--r-- | data/nm-priv-helper.service.in | 79 |
1 files changed, 79 insertions, 0 deletions
diff --git a/data/nm-priv-helper.service.in b/data/nm-priv-helper.service.in new file mode 100644 index 00000000..aa028e6c --- /dev/null +++ b/data/nm-priv-helper.service.in @@ -0,0 +1,79 @@ +[Unit] +Description=NetworkManager Privileged Helper + +# +# nm-priv-helper exists for privilege separation. It allows to run +# NetworkManager without certain capabilities, and ask nm-priv-helper +# for special operations where more privileges are required. +# + +# While nm-priv-helper has privileges that NetworkManager has not, it +# does not mean that itself should run totally unconstrained. On the +# contrary, it also should only have permissions it requires. +# +# nm-priv-helper rejects all requests that come from any other than the +# name owner of "org.freedesktop.NetworkManager" (that is, +# NetworkManager process itself). It is thus only an implementation +# detail and provides no public API to the user. + +[Service] +Type=dbus +BusName=org.freedesktop.nm-priv-helper +ExecStart=@libexecdir@/nm-priv-helper +NotifyAccess=main + +# Extra configuration options. Set via `systemctl edit +# nm-priv-helper.service`: +# +# FOR TESTING ONLY: disable authentication to allow requests from +# everybody. Don't set this outside of testing! +#Environment=NM_PRIV_HELPER_NO_AUTH_FOR_TESTING=1 +# +# The logging level for debug messages (to stdout). +#Environment=NM_PRIV_HELPER_LOG=TRACE +# +# nm-priv-helper will exit on idle after timeout. Set timeout here or +# set to 2147483647 for infinity. + +#Environment=NM_PRIV_HELPER_IDLE_TIMEOUT_MSEC=10000 + + +# Restrict: +AmbientCapabilities= +CapabilityBoundingSet= +PrivateDevices=true +PrivateMounts=true +PrivateNetwork=true +PrivateTmp=true +ProtectClock=true +ProtectControlGroups=true +ProtectHome=true +ProtectHostname=true +ProtectKernelLogs=true +ProtectKernelModules=true +ProtectKernelTunables=true +ProtectSystem=strict +RestrictAddressFamilies= +RestrictNamespaces=true +SystemCallFilter=~@clock +SystemCallFilter=~@cpu-emulation +SystemCallFilter=~@debug +SystemCallFilter=~@module +SystemCallFilter=~@mount +SystemCallFilter=~@obsolete +SystemCallFilter=~@privileged +SystemCallFilter=~@raw-io +SystemCallFilter=~@reboot +SystemCallFilter=~@swap +NoNewPrivileges=true +SupplementaryGroups= + +# Grant: +CapabilityBoundingSet=CAP_DAC_OVERRIDE +PrivateUsers=no +RestrictAddressFamilies=AF_UNIX +SystemCallFilter=@resources + + +[Install] +Alias=dbus-org.freedesktop.nm-priv-helper.service |