This unit is provided by:
Options
-
[Service]
-
ExecStart=-/lib/systemd/systemd-coredump
-
ExecStart=-/usr/lib/systemd/systemd-coredump
-
IPAddressDeny=any
-
LockPersonality
Introduced in systemd 235=yes -
MemoryDenyWriteExecute
Introduced in systemd 231=yes -
Nice=9
-
NoNewPrivileges
Introduced in systemd 239=yes -
OOMScoreAdjust=500
-
PrivateDevices
Introduced in systemd 209=yes -
PrivateNetwork=yes
-
PrivateTmp=yes
-
ProtectControlGroups
Introduced in systemd 232=yes -
ProtectHome
Introduced in systemd 214=yes -
ProtectHostname
Introduced in systemd 242=yes -
ProtectKernelLogs
Introduced in systemd 244=yes -
ProtectKernelModules
Introduced in systemd 232=yes -
ProtectKernelTunables
Introduced in systemd 232=yes -
ProtectSystem
Introduced in systemd 214=strict -
RestrictAddressFamilies=AF_UNIX
-
RestrictRealtime
Introduced in systemd 231=yes -
RestrictSUIDSGID
Introduced in systemd 242=yes -
RuntimeMaxSec=5min
-
StateDirectory=systemd/coredump
-
SystemCallArchitectures=native
-
SystemCallErrorNumber=EPERM
-
SystemCallFilter=@system-service @mount
-
-
[Unit]
-
After=systemd-journald.socket
-
Before=shutdown.target
-
Conflicts=shutdown.target
-
DefaultDependencies=no
-
Description=Process Core Dump
-
Documentation=man:systemd-coredump(8)
-
Requires=systemd-journald.socket
-
Additionnal notes
Nothing here.