Use PrivateDevices instead of DeviceAllow

See 13805
This commit is contained in:
Craig Andrews 2014-11-28 12:36:17 -05:00
parent 11b652acb3
commit 1ac3b74405

View File

@ -16,8 +16,7 @@ LimitNOFILE = 32768
# Hardening
PrivateTmp = yes
DeviceAllow = /dev/null rw
DeviceAllow = /dev/urandom r
PrivateDevices = yes
InaccessibleDirectories = /home
ReadOnlyDirectories = /
ReadWriteDirectories = @LOCALSTATEDIR@/lib/tor