We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 393e018 commit 2059072Copy full SHA for 2059072
man/openrc-run.8
@@ -259,6 +259,11 @@ which will export
259
.Ar $NOTIFY_SOCKET
260
and listen for notifications. At the moment supporting
261
.Ar READY=1 Ns .
262
+.It Ar no_new_privs
263
+Set no_new_privs on the daemon process, preventing it from gaining any
264
+additional privilege, including through setuid/setgid binaries, file
265
+capabilities, etc. See
266
+.Xr capabilities 7 .
267
.El
268
.Sh DEPENDENCIES
269
You should define a
0 commit comments