anag_factory d42d2589bb Accepting request 1354964 from server:proxy
- Comprehensive systemd service hardening (bnc#1212862 and boo#1263916)
  * Add CAP_DAC_READ_SEARCH to AmbientCapabilities/CapabilityBoundingSet
    to allow reading certificates from restricted dynamic paths.
  * Ensures v2ray-plugin can access Let's Encrypt keys reliably.
  * Restrict root powers using CapabilityBoundingSet (minimal privileges).
  * Isolate filesystem via ProtectSystem=full and ProtectHome=true.
  * Whitelist binary and config access with ReadOnlyPaths.
  * Disable kernel/device modifications (ProtectKernel*, PrivateDevices).
  * Introduce SELinux and AppArmor as optional security hardening schemes, 
    and add shadowsocks-libev-selinux and shadowsocks-libev-apparmory
    subpackages.
- Integrate shadowsocks-sysuser for proper non-privileged user handling
  (boo#1264355).

OBS-URL: https://build.opensuse.org/request/show/1354964
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shadowsocks-rust?expand=0&rev=20
2026-05-27 14:13:55 +00:00
S
Description
No description provided
92 MiB
Languages
Diff 100%