Explorar o código

add NoNewPrivileges=yes & CAP_NET_RAW

unknowndev233 %!s(int64=5) %!d(string=hai) anos
pai
achega
882320e45a
Modificáronse 1 ficheiros con 2 adicións e 1 borrados
  1. 2 1
      release/config/systemd/v2ray.service

+ 2 - 1
release/config/systemd/v2ray.service

@@ -14,7 +14,8 @@ Type=simple
 # More discussion at https://github.com/v2ray/v2ray-core/issues/1011
 User=root
 #User=v2ray
-#AmbientCapabilities=CAP_NET_BIND_SERVICE
+CapabilityBoundingSet=CAP_NET_BIND_SERVICE CAP_NET_RAW
+NoNewPrivileges=yes
 ExecStart=/usr/bin/v2ray/v2ray -config /etc/v2ray/config.json
 Restart=on-failure
 # Don't restart in the case of configuration error