Browse Source

add NoNewPrivileges=yes & CAP_NET_RAW

unknowndev233 5 years ago
parent
commit
882320e45a
1 changed files with 2 additions and 1 deletions
  1. 2 1
      release/config/systemd/v2ray.service

+ 2 - 1
release/config/systemd/v2ray.service

@@ -14,7 +14,8 @@ Type=simple
 # More discussion at https://github.com/v2ray/v2ray-core/issues/1011
 User=root
 #User=v2ray
-#AmbientCapabilities=CAP_NET_BIND_SERVICE
+CapabilityBoundingSet=CAP_NET_BIND_SERVICE CAP_NET_RAW
+NoNewPrivileges=yes
 ExecStart=/usr/bin/v2ray/v2ray -config /etc/v2ray/config.json
 Restart=on-failure
 # Don't restart in the case of configuration error