-
Notifications
You must be signed in to change notification settings - Fork 18
Backport ProtectSystem=strict reversion to v234 #93
Conversation
Backport of #91. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There are a few missed reversions; not sure if they're important.
This doesn't revert units/systemd-journal-gatewayd.service.in
; should it?
@@ -23,7 +23,7 @@ RuntimeMaxSec=5min | |||
PrivateTmp=yes | |||
PrivateDevices=yes | |||
PrivateNetwork=yes | |||
ProtectSystem=strict | |||
ProtectSystem=full |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Should ReadWritePaths=/var/lib/systemd/coredump
be dropped?
@@ -18,7 +18,7 @@ WatchdogSec=3min | |||
PrivateTmp=yes | |||
PrivateDevices=yes | |||
PrivateNetwork=yes | |||
ProtectSystem=strict | |||
ProtectSystem=full |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Should ReadWritePaths=/var/log/journal/remote
be dropped?
@@ -29,7 +29,7 @@ WatchdogSec=3min | |||
CapabilityBoundingSet=CAP_SETUID CAP_SETGID CAP_SETPCAP CAP_CHOWN CAP_DAC_OVERRIDE CAP_FOWNER CAP_NET_RAW CAP_NET_BIND_SERVICE | |||
PrivateTmp=yes | |||
PrivateDevices=yes | |||
ProtectSystem=strict | |||
ProtectSystem=full |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
ReadWritePaths=/run/systemd
?
@@ -26,7 +26,7 @@ WatchdogSec=3min | |||
CapabilityBoundingSet=CAP_SYS_TIME CAP_SETUID CAP_SETGID CAP_SETPCAP CAP_CHOWN CAP_DAC_OVERRIDE CAP_FOWNER | |||
PrivateTmp=yes | |||
PrivateDevices=yes | |||
ProtectSystem=strict | |||
ProtectSystem=full |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
ReadWritePaths=/var/lib/systemd
?
…rvices" This reverts commit c7fb922. See bugs: - coreos/bugs#2193 - coreos/bugs#2190 - systemd#7082
Updated via reverting the commit instead of cherry-picking the other reversion commit. Should be complete now. I'm going to triple check PR 91 and make sure there isn't anything missed it that, given how uncleanly it applied. Edit: #91 is good. Some things switched to using |
This was added in c7fb922 but causes
some bugs, so revert until they are resolved.
Bugs: