From af7a86b8a6b6510264b7ac0ae6a1e1d37d510ef5 Mon Sep 17 00:00:00 2001 From: Yu Watanabe Date: Sat, 13 Aug 2022 17:18:55 +0900 Subject: network/tuntap: save tun or tap file descriptor in fd store --- units/systemd-networkd.service.in | 1 + 1 file changed, 1 insertion(+) (limited to 'units/systemd-networkd.service.in') diff --git a/units/systemd-networkd.service.in b/units/systemd-networkd.service.in index 95dd2665b2..d15129e7f0 100644 --- a/units/systemd-networkd.service.in +++ b/units/systemd-networkd.service.in @@ -25,6 +25,7 @@ CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_BROADCAST CAP_N DeviceAllow=char-* rw ExecStart=!!{{ROOTLIBEXECDIR}}/systemd-networkd ExecReload=networkctl reload +FileDescriptorStoreMax=512 LockPersonality=yes MemoryDenyWriteExecute=yes NoNewPrivileges=yes -- cgit v1.2.1