Skip to content
This repository has been archived by the owner on Sep 18, 2020. It is now read-only.

sysctl: Revert new protections from systemd 241 #72

Merged
merged 1 commit into from Apr 12, 2019
Merged

sysctl: Revert new protections from systemd 241 #72

merged 1 commit into from Apr 12, 2019

Conversation

dm0-
Copy link
Contributor

@dm0- dm0- commented Apr 12, 2019

Undo systemd/systemd#11442 for coreos/bugs#2577 to avoid breaking users at this point in the Container Linux life cycle. The security improvements are left enabled in Fedora 30, so Fedora CoreOS will benefit from the upstream change.

With systemd 241, new Linux 4.19 protections are enabled so that
e.g. root can't open files with O_CREAT in /tmp if they are owned
by another user.  This security improvement is also a backwards
incompatible change, so we're opting to preserve existing behavior
at this point in the Container Linux life cycle.
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
2 participants