Bug#885141: tor: systemd unit files should confine tor as much as possible

2017-12-24 Thread Nicolas Braud-Santoni
As discussed on IRC, here is a new patch that drops PermissionsStartOnly. I also updated the backport script. commit eaf325d3cf3a42033e32b5535599a3f0427fa519 Author: Nicolas Braud-Santoni Date: Sun Dec 24 17:07:12 2017 +0100 debian/systemd: Drop

Bug#885141: tor: systemd unit files should confine tor as much as possible

2017-12-24 Thread Nicolas Braud-Santoni
PS: Here is a patch for the backports script. I was unable to test it, as the script hardcodes your directory layout. On Sun, Dec 24, 2017 at 03:36:59PM +0100, Nicolas Braud-Santoni wrote: > Package: tor > Version: 0.3.2.8-rc-1 > Severity: normal > Tags: patch stretch buster sid > >

Bug#885141: tor: systemd unit files should confine tor as much as possible

2017-12-24 Thread Nicolas Braud-Santoni
Package: tor Version: 0.3.2.8-rc-1 Severity: normal Tags: patch stretch buster sid -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi weasel, Here is a patch for the systemd unit files that we ship with tor. It prevents tor from having read-write access to /var/run, and from having access to