Blame SOURCES/dovecot-2.2.22-systemd_w_protectsystem.patch

70765b
diff -up dovecot-2.2.28/dovecot.service.in.systemd_w_protectsystem dovecot-2.2.28/dovecot.service.in
70765b
--- dovecot-2.2.28/dovecot.service.in.systemd_w_protectsystem	2017-02-27 10:00:14.647423500 +0100
70765b
+++ dovecot-2.2.28/dovecot.service.in	2017-02-27 10:02:18.051377067 +0100
70765b
@@ -20,8 +20,8 @@ ExecReload=@bindir@/doveadm reload
70765b
 ExecStop=@bindir@/doveadm stop
70765b
 PrivateTmp=true
70765b
 NonBlocking=yes
70765b
-# Enable this if your systemd is new enough to support it:
70765b
-#ProtectSystem=full
70765b
+# Enable this if your systemd is new enough to support it: (it will make /usr /boot /etc read only for dovecot)
70765b
+ProtectSystem=full
70765b
 
70765b
 # You can add environment variables with e.g.:
70765b
 #Environment='CORE_OUTOFMEM=1'