KDE
This commit is contained in:
		
							parent
							
								
									6844d75772
								
							
						
					
					
						commit
						7385e0e1b2
					
				
					 57 changed files with 1133 additions and 0 deletions
				
			
		|  | @ -0,0 +1,2 @@ | |||
| [Coredump] | ||||
| Storage=none | ||||
|  | @ -0,0 +1,28 @@ | |||
| [Service] | ||||
| # Hardening | ||||
| CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE CAP_AUDIT_WRITE CAP_KILL CAP_SYS_CHROOT | ||||
| LockPersonality=true | ||||
| MemoryDenyWriteExecute=true | ||||
| #PrivateDevices=true #breaks tun usage | ||||
| #ProtectProc=invisible | ||||
| PrivateTmp=yes | ||||
| ProtectClock=true | ||||
| ProtectControlGroups=true | ||||
| ProtectHome=read-only | ||||
| ProtectKernelLogs=true | ||||
| #ProtectKernelModules=true | ||||
| #ProtectSystem=strict | ||||
| #ReadOnlyPaths=/etc/NetworkManager | ||||
| ReadOnlyPaths=-/home | ||||
| #ReadWritePaths=-/etc/NetworkManager/system-connections | ||||
| ReadWritePaths=-/etc/sysconfig/network-scripts | ||||
| ReadWritePaths=/var/lib/NetworkManager | ||||
| ReadWritePaths=-/var/run/NetworkManager | ||||
| ReadWritePaths=-/run/NetworkManager | ||||
| RemoveIPC=true | ||||
| RestrictNamespaces=true | ||||
| RestrictRealtime=true | ||||
| RestrictSUIDSGID=true | ||||
| SystemCallArchitectures=native | ||||
| SystemCallFilter=@system-service | ||||
| UMask=0077 | ||||
|  | @ -0,0 +1,6 @@ | |||
| [Unit] | ||||
| Description=Update user Flatpaks | ||||
| 
 | ||||
| [Service] | ||||
| Type=oneshot | ||||
| ExecStart=/usr/bin/flatpak --user update -y | ||||
|  | @ -0,0 +1,9 @@ | |||
| [Unit] | ||||
| Description=Update user Flatpaks daily | ||||
| 
 | ||||
| [Timer] | ||||
| OnCalendar=daily | ||||
| Persistent=true | ||||
| 
 | ||||
| [Install] | ||||
| WantedBy=timers.target | ||||
|  | @ -0,0 +1,4 @@ | |||
| [zram0] | ||||
| zram-fraction = 1 | ||||
| max-zram-size = 8192 | ||||
| compression-algorithm = zstd | ||||
		Loading…
	
	Add table
		Add a link
		
	
		Reference in a new issue
	
	 mustard
						mustard