man: ProtectHome= protects /root as well

(cherry picked from commit 5833143708)
This commit is contained in:
Christian Hesse
2015-07-07 07:33:50 -04:00
committed by Zbigniew Jędrzejewski-Szmek
parent 3fd4f8ef4d
commit bc8212cae8
+3 -2
View File
@@ -858,9 +858,10 @@
<listitem><para>Takes a boolean argument or
<literal>read-only</literal>. If true, the directories
<filename>/home</filename> and <filename>/run/user</filename>
<filename>/home</filename>, <filename>/root</filename> and
<filename>/run/user</filename>
are made inaccessible and empty for processes invoked by this
unit. If set to <literal>read-only</literal>, the two
unit. If set to <literal>read-only</literal>, the three
directories are made read-only instead. It is recommended to
enable this setting for all long-running services (in
particular network-facing ones), to ensure they cannot get