What is Nostr?
Lennart Poettering /
npub1rk2…zenj
2024-12-11 09:15:34
in reply to nevent1q…vxsf

Lennart Poettering on Nostr: …that SystemCallFilter= in unit files understands. "systemd-analyze architectures" ...

…that SystemCallFilter= in unit files understands. "systemd-analyze architectures" lists architectures recognized by systemd (for use with ConditionArchitecture=) and "systemd-analyze filesystem" lists file system types understood by systemd for its file system access restriction logic.

And then there's "systemd-analyze capability" that allows listing process capabilities the local kernel and systemd know. Process capabilities are finer grained permissions that each process can possess or lack.
Author Public Key
npub1rk2uxtv6nk262nucavh259t085a8rhzfaj3vjc9jhzvkyav0rnqqxqzenj