Skip to content

Commit 680b0cd

Browse files
committed
MDEV-36721: remove PrivateDevices=false from systemd services
The association between PrivateDevices=false and NoNewPrivileges as an old mistake in the kernel that has been now corrected. This was in 2019 via Debian bug #911152.
1 parent 9f64b29 commit 680b0cd

File tree

2 files changed

+0
-8
lines changed

2 files changed

+0
-8
lines changed

support-files/mariadb.service.in

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -51,10 +51,6 @@ Group=mysql
5151
# These are enabled by default
5252
AmbientCapabilities=CAP_IPC_LOCK
5353

54-
# PrivateDevices=true implies NoNewPrivileges=true and
55-
# SUID auth_pam_tool suddenly doesn't do setuid anymore
56-
PrivateDevices=false
57-
5854
# Prevent writes to /usr, /boot, and /etc
5955
ProtectSystem=full
6056

support-files/mariadb@.service.in

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -181,10 +181,6 @@ PrivateNetwork=false
181181
# These are enabled by default
182182
AmbientCapabilities=CAP_IPC_LOCK
183183

184-
# PrivateDevices=true implies NoNewPrivileges=true and
185-
# SUID auth_pam_tool suddenly doesn't do setuid anymore
186-
PrivateDevices=false
187-
188184
# Prevent writes to /usr, /boot, and /etc
189185
ProtectSystem=full
190186

0 commit comments

Comments
 (0)