power-profiles-daemon/data/power-profiles-daemon.service.in

49 lines
1.2 KiB
SYSTEMD
Raw Normal View History

2020-07-06 12:37:41 +02:00
[Unit]
Description=Power Profiles daemon
Conflicts=tuned.service tlp.service auto-cpufreq.service system76-power.service
After=multi-user.target display-manager.target
2020-07-06 12:37:41 +02:00
[Service]
Type=dbus
BusName=org.freedesktop.UPower.PowerProfiles
# To enable debugging add a -vv to the ExecStart line
2020-07-06 12:37:41 +02:00
ExecStart=@libexecdir@/power-profiles-daemon
2020-09-09 13:00:27 +02:00
Restart=on-failure
# This always corresponds to /var/lib/power-profiles-daemon
StateDirectory=power-profiles-daemon
2020-07-06 12:37:41 +02:00
# Lockdown
CapabilityBoundingSet=CAP_SYS_ADMIN
2024-03-26 20:32:10 +00:00
DevicePolicy=closed
IPAddressDeny=any
2024-03-26 20:32:10 +00:00
KeyringMode=private
LockPersonality=yes
MemoryDenyWriteExecute=yes
NoNewPrivileges=yes
PrivateDevices=yes
PrivateTmp=yes
PrivateNetwork=yes
PrivateUsers=yes
2024-03-26 20:32:10 +00:00
ProtectClock=yes
ProtectControlGroups=yes
ProtectHome=yes
ProtectHostname=yes
ProtectKernelLogs=yes
ProtectKernelModules=yes
ProtectProc=invisible
2020-07-06 12:37:41 +02:00
ProtectSystem=strict
2024-03-26 20:32:10 +00:00
RemoveIPC=yes
2020-07-06 12:37:41 +02:00
RestrictAddressFamilies=AF_UNIX AF_LOCAL AF_NETLINK
MemoryDenyWriteExecute=true
RestrictRealtime=true
2024-03-26 20:32:10 +00:00
RestrictNamespaces=yes
RestrictRealtime=yes
RestrictSUIDSGID=yes
SystemCallFilter=@system-service
SystemCallFilter=~@resources @privileged
SystemCallErrorNumber=EPERM
SystemCallArchitectures=native
[Install]
WantedBy=graphical.target