summaryrefslogtreecommitdiff
path: root/man/cgroup-sandboxing.xml
Commit message (Collapse)AuthorAgeFilesLines
* man: note that cgroup-based sandboxing is not bypassed by '+'Luca Boccassi2023-01-181-0/+16
DeviceAllow= and others are applied to the whole cgroup via bpf, so using '+' on an Exec line will not bypass them. Explain this in the manpage. Fixes https://github.com/systemd/systemd/issues/26035