This unit is provided by:
Options
-
[Service]
-
AmbientCapabilities=
-
BindReadOnlyPaths=/etc /run/systemd glibc-locales-2.35-163 public-inbox-description-repo1 public-inbox-description-repo2 /usr/bin/dash:/bin/sh /nix/store
-
CapabilityBoundingSet=
-
DeviceAllow=
-
Environment=PERL_INLINE_DIRECTORY=/run/public-inbox-init/perl-inline
-
ExecStart=/usr/bin/public-inbox-init-start
-
Group=public-inbox
-
LockPersonality
Introduced in systemd 235=yes -
MemoryDenyWriteExecute
Introduced in systemd 231=yes -
MountAPIVFS=yes
-
NoNewPrivileges
Introduced in systemd 239=yes -
NonBlocking=yes
-
PrivateDevices
Introduced in systemd 209=yes -
PrivateMounts=yes
-
PrivateNetwork=yes
-
PrivateTmp=yes
-
PrivateUsers=yes
-
ProcSubset
Introduced in systemd 247=pid -
ProtectClock
Introduced in systemd 245=yes -
ProtectControlGroups
Introduced in systemd 232=yes -
ProtectHome
Introduced in systemd 214=yes -
ProtectHostname
Introduced in systemd 242=yes -
ProtectKernelLogs
Introduced in systemd 244=yes -
ProtectKernelModules
Introduced in systemd 232=yes -
ProtectKernelTunables
Introduced in systemd 232=yes -
ProtectProc
Introduced in systemd 247=invisible -
RemainAfterExit=yes
-
RemoveIPC
Introduced in systemd 232=yes -
RestrictAddressFamilies=AF_UNIX
-
RestrictNamespaces
Introduced in systemd 233=yes -
RestrictRealtime
Introduced in systemd 231=yes -
RestrictSUIDSGID
Introduced in systemd 242=yes -
RootDirectory=/var/empty
-
RuntimeDirectory=public-inbox-init/perl-inline
-
RuntimeDirectoryMode=700
-
StateDirectory=public-inbox/.public-inbox public-inbox/.public-inbox/emergency public-inbox/inboxes public-inbox
-
StateDirectoryMode=0750
-
SystemCallArchitectures=native
-
SystemCallFilter=@system-service ~@aio ~@chown ~@keyring ~@memlock ~@resources
-
TemporaryFileSystem=/
-
Type=oneshot
-
UMask=0066
-
User=public-inbox
-
WorkingDirectory=/var/lib/public-inbox
-
-
[Unit]
Additionnal notes
Nothing here.