summary refs log tree commit diff
path: root/data/nm-priv-helper.service.in
diff options
context:
space:
mode:
authorMichael Biebl <biebl@debian.org>2022-01-13 22:30:39 +0100
committerMichael Biebl <biebl@debian.org>2022-01-13 22:30:39 +0100
commit88c227d90a6b7b388c5c85d72802a0ca8f05ed5c (patch)
tree71f32df6617802270e8a78574bd8e1637dc532f4 /data/nm-priv-helper.service.in
parente74c568b07b50b97873fb4ee1d776dedefbd54d6 (diff)
New upstream version 1.34.0 upstream/1.34.0
Diffstat (limited to 'data/nm-priv-helper.service.in')
-rw-r--r--data/nm-priv-helper.service.in79
1 files changed, 79 insertions, 0 deletions
diff --git a/data/nm-priv-helper.service.in b/data/nm-priv-helper.service.in
new file mode 100644
index 00000000..aa028e6c
--- /dev/null
+++ b/data/nm-priv-helper.service.in
@@ -0,0 +1,79 @@
+[Unit]
+Description=NetworkManager Privileged Helper
+
+#
+# nm-priv-helper exists for privilege separation. It allows to run
+# NetworkManager without certain capabilities, and ask nm-priv-helper
+# for special operations where more privileges are required.
+#
+
+# While nm-priv-helper has privileges that NetworkManager has not, it
+# does not mean that itself should run totally unconstrained. On the
+# contrary, it also should only have permissions it requires.
+#
+# nm-priv-helper rejects all requests that come from any other than the
+# name owner of "org.freedesktop.NetworkManager" (that is,
+# NetworkManager process itself). It is thus only an implementation
+# detail and provides no public API to the user.
+
+[Service]
+Type=dbus
+BusName=org.freedesktop.nm-priv-helper
+ExecStart=@libexecdir@/nm-priv-helper
+NotifyAccess=main
+
+# Extra configuration options. Set via `systemctl edit
+# nm-priv-helper.service`:
+#
+# FOR TESTING ONLY: disable authentication to allow requests from
+# everybody. Don't set this outside of testing!
+#Environment=NM_PRIV_HELPER_NO_AUTH_FOR_TESTING=1
+#
+# The logging level for debug messages (to stdout).
+#Environment=NM_PRIV_HELPER_LOG=TRACE
+#
+# nm-priv-helper will exit on idle after timeout. Set timeout here or
+# set to 2147483647 for infinity.
+
+#Environment=NM_PRIV_HELPER_IDLE_TIMEOUT_MSEC=10000
+
+
+# Restrict:
+AmbientCapabilities=
+CapabilityBoundingSet=
+PrivateDevices=true
+PrivateMounts=true
+PrivateNetwork=true
+PrivateTmp=true
+ProtectClock=true
+ProtectControlGroups=true
+ProtectHome=true
+ProtectHostname=true
+ProtectKernelLogs=true
+ProtectKernelModules=true
+ProtectKernelTunables=true
+ProtectSystem=strict
+RestrictAddressFamilies=
+RestrictNamespaces=true
+SystemCallFilter=~@clock
+SystemCallFilter=~@cpu-emulation
+SystemCallFilter=~@debug
+SystemCallFilter=~@module
+SystemCallFilter=~@mount
+SystemCallFilter=~@obsolete
+SystemCallFilter=~@privileged
+SystemCallFilter=~@raw-io
+SystemCallFilter=~@reboot
+SystemCallFilter=~@swap
+NoNewPrivileges=true
+SupplementaryGroups=
+
+# Grant:
+CapabilityBoundingSet=CAP_DAC_OVERRIDE
+PrivateUsers=no
+RestrictAddressFamilies=AF_UNIX
+SystemCallFilter=@resources
+
+
+[Install]
+Alias=dbus-org.freedesktop.nm-priv-helper.service