1
0

x-ui.service.rhel 4.7 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495
  1. [Unit]
  2. Description=x-ui Service
  3. After=network.target
  4. Wants=network.target
  5. StartLimitIntervalSec=180
  6. StartLimitBurst=10
  7. [Service]
  8. EnvironmentFile=-/etc/sysconfig/x-ui
  9. Environment="XRAY_VMESS_AEAD_FORCED=false"
  10. Type=simple
  11. WorkingDirectory=/usr/local/x-ui/
  12. ExecStart=/usr/local/x-ui/x-ui
  13. ExecReload=/bin/kill -USR1 $MAINPID
  14. Restart=on-failure
  15. RestartSec=5s
  16. # The panel intentionally stays root: it supervises the Xray child processes,
  17. # edits netfilter state and reads TLS private keys. These settings only bound
  18. # what a panel-level flaw can reach.
  19. #
  20. # PrivateTmp=yes is deliberately absent: the web updater writes its script into
  21. # /tmp and hands the absolute path to a "systemd-run" transient unit, which
  22. # does not share this service's private /tmp (the download would vanish).
  23. NoNewPrivileges=yes
  24. ProtectSystem=full
  25. # Default stores: DB/update status/node-token in XUI_DB_FOLDER (/etc/x-ui),
  26. # xray binary/config/geo in XUI_BIN_FOLDER under /usr/local/x-ui, logs in
  27. # XUI_LOG_FOLDER (/var/log/x-ui). These are the plain-install defaults and the
  28. # floor, not the whole list: install.sh and update.sh regenerate a drop-in
  29. # (x-ui.service.d/10-xui-sandbox.conf) with the folders resolved from the XUI_*
  30. # variables, so a relocated XUI_DB_FOLDER or XUI_LOG_FOLDER stays writable and
  31. # the list survives an update instead of being reset to these defaults. Changing
  32. # one of those variables in the env file is not enough by itself: the drop-in has
  33. # to be refreshed as well, i.e. install or update the panel again.
  34. # Add local extras in your own drop-in (e.g. 20-local.conf).
  35. # The leading '-' keeps the unit startable if a path does not exist yet.
  36. # What ProtectSystem=full covers, precisely: /usr, /boot, /efi and /etc become
  37. # read-only, everything else stays writable. So this list matters for stores
  38. # under those trees -- the default main folder under /usr/local is one.
  39. #
  40. # The in-panel updater is expected to leave this sandbox: it runs update.sh
  41. # through a transient systemd-run unit, which does not inherit these settings.
  42. # Its plain-child fallback (taken when systemd-run is unavailable) cannot work
  43. # here -- update.sh stages the release archive beside the main folder, replaces
  44. # /usr/bin/x-ui and calls the package manager -- so it stops with one clear
  45. # message instead of failing halfway, and the sandbox deliberately does not
  46. # grant /usr or /etc to accommodate it.
  47. # ReadWritePaths= requires systemd >= 231; ReadWriteDirectories= is the deprecated
  48. # alias for older systemd, needed so ProtectSystem=full keeps /etc/x-ui writable.
  49. ReadWritePaths=-/etc/x-ui -/usr/local/x-ui -/var/log/x-ui
  50. ReadWriteDirectories=-/etc/x-ui -/usr/local/x-ui -/var/log/x-ui
  51. ProtectKernelTunables=yes
  52. ProtectKernelModules=yes
  53. ProtectKernelLogs=yes
  54. ProtectClock=yes
  55. ProtectHostname=yes
  56. # read-only rather than yes: installs keep TLS certs under /root/cert, and the
  57. # panel must still be able to read them.
  58. ProtectHome=read-only
  59. LockPersonality=yes
  60. RestrictRealtime=yes
  61. RestrictSUIDSGID=yes
  62. RestrictNamespaces=yes
  63. UMask=0077
  64. # AF_NETLINK for interface/route lookups and the ip(8) child used by the
  65. # AmneziaWG IPv6-alias feature.
  66. RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX AF_NETLINK
  67. # NET_ADMIN for ip(8)/tproxy, NET_BIND_SERVICE for ports below 1024, NET_RAW
  68. # for raw sockets and SO_BINDTODEVICE.
  69. #
  70. # DAC_OVERRIDE has to stay. The panel runs as root, but a bounding set is
  71. # subtracted from root's own privileges too: without it root can only read a
  72. # file when the owner/group/other bits let uid 0 through, and any TLS private
  73. # key belonging to another account becomes unreadable -- a certificate issued to
  74. # Caddy, an acme.sh home, any 0600 file that root does not own. TLS then fails
  75. # quietly: the panel listener catches the tls.LoadX509KeyPair error, logs it and
  76. # keeps serving plain HTTP, and every Xray inbound using that key stops. Those
  77. # reads worked before the sandbox because the panel is root.
  78. # DAC_READ_SEARCH is deliberately absent: directory search is already covered by
  79. # DAC_OVERRIDE, so it would only widen the set without adding anything.
  80. CapabilityBoundingSet=CAP_DAC_OVERRIDE CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_RAW
  81. SystemCallArchitectures=native
  82. # No seccomp whitelist here on purpose. @system-service needs systemd >= 239
  83. # (other @-named groups exist since 231), and older systemd does not ignore an
  84. # unknown group name gracefully: on
  85. # <231 the name fails to resolve and the filter stays the built-in whitelist of
  86. # execve/exit/exit_group/rt_sigreturn/sigreturn, on 231..238 it degrades to
  87. # @default -- either way the panel then gets EPERM on read/openat/mmap/clone and
  88. # cannot start. install.sh and update.sh add SystemCallFilter=@system-service and
  89. # SystemCallErrorNumber=EPERM to the generated drop-in, but only when
  90. # "systemctl --version" reports 239 or newer.
  91. [Install]
  92. WantedBy=multi-user.target