man: LockPersonality= implies NoNewPrivileges=

This commit is contained in:
Yu Watanabe 2017-12-19 12:48:54 +09:00
parent bf0e0a4df2
commit 69b528832a
1 changed files with 2 additions and 1 deletions

View File

@ -381,7 +381,8 @@ CapabilityBoundingSet=~CAP_B CAP_C</programlisting>
<varname>SystemCallArchitectures=</varname>, <varname>RestrictAddressFamilies=</varname>,
<varname>RestrictNamespaces=</varname>, <varname>PrivateDevices=</varname>,
<varname>ProtectKernelTunables=</varname>, <varname>ProtectKernelModules=</varname>,
<varname>MemoryDenyWriteExecute=</varname>, or <varname>RestrictRealtime=</varname> are specified. Also see
<varname>MemoryDenyWriteExecute=</varname>, <varname>RestrictRealtime=</varname>, or
<varname>LockPersonality=</varname> are specified. Also see
<ulink url="https://www.kernel.org/doc/html/latest/userspace-api/no_new_privs.html">No New Privileges
Flag</ulink>. </para></listitem>
</varlistentry>