xray: allow binding lower ports

Set CapabilityBoundingSet, AmbientCapabilities and NoNewPrivileges as described in XTLS/xray-install.
This commit is contained in:
Marillindië 2023-06-06 03:12:48 +00:00 committed by Emery Hemingway
parent 954d3794ae
commit e394dc22f9

View file

@ -90,6 +90,9 @@ with lib;
serviceConfig = {
DynamicUser = true;
ExecStart = "${cfg.package}/bin/xray -config ${settingsFile}";
CapabilityBoundingSet = "CAP_NET_ADMIN CAP_NET_BIND_SERVICE";
AmbientCapabilities = "CAP_NET_ADMIN CAP_NET_BIND_SERVICE";
NoNewPrivileges = true;
};
};
};