Skip to content

Commit 2059072

Browse files
WhyNotHugonavi-desu
authored andcommitted
Document the no_new_privs setting
1 parent 393e018 commit 2059072

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

man/openrc-run.8

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -259,6 +259,11 @@ which will export
259259
.Ar $NOTIFY_SOCKET
260260
and listen for notifications. At the moment supporting
261261
.Ar READY=1 Ns .
262+
.It Ar no_new_privs
263+
Set no_new_privs on the daemon process, preventing it from gaining any
264+
additional privilege, including through setuid/setgid binaries, file
265+
capabilities, etc. See
266+
.Xr capabilities 7 .
262267
.El
263268
.Sh DEPENDENCIES
264269
You should define a

0 commit comments

Comments
 (0)