Skip to content
  • Zbigniew Jędrzejewski-Szmek's avatar
    Make PrivateTmp dirs also inaccessible from the outside · d34cd374
    Zbigniew Jędrzejewski-Szmek authored
    Currently, PrivateTmp=yes means that the service cannot see the /tmp
    shared by rest of the system and is isolated from other services using
    PrivateTmp, but users can access and modify /tmp as seen by the
    service.
    
    Move the private /tmp and /var/tmp directories into a 0077-mode
    directory. This way unpriviledged users on the system cannot see (or
    modify) /tmp as seen by the service.
    d34cd374