factory
- Comprehensive systemd service hardening (bnc#1212862 and boo#1263916)
* Add CAP_DAC_READ_SEARCH to AmbientCapabilities/CapabilityBoundingSet
to allow reading certificates from restricted dynamic paths.
* Ensures v2ray-plugin can access Let's Encrypt keys reliably.
* Restrict root powers using CapabilityBoundingSet (minimal privileges).
* Isolate filesystem via ProtectSystem=full and ProtectHome=true.
* Whitelist binary and config access with ReadOnlyPaths.
* Disable kernel/device modifications (ProtectKernel*, PrivateDevices).
* Introduce SELinux and AppArmor as optional security hardening schemes,
and add shadowsocks-libev-selinux and shadowsocks-libev-apparmory
subpackages.
- Integrate shadowsocks-sysuser for proper non-privileged user handling
(boo#1264355).
OBS-URL: https://build.opensuse.org/request/show/1354964
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shadowsocks-rust?expand=0&rev=20
Description
No description provided
Languages
Diff
100%