]> git.ipfire.org Git - thirdparty/systemd.git/commit
units: set NoNewPrivileges= for all long-running services
authorLennart Poettering <lennart@poettering.net>
Mon, 12 Nov 2018 16:19:48 +0000 (17:19 +0100)
committerZbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl>
Tue, 18 Dec 2018 13:21:35 +0000 (14:21 +0100)
commit64d7f7b4a15f1534fb19fda6b601fec50783bee4
tree1fa694aa51c8d848adeeb0dd991363d5595b059b
parent52ef7bbbe653aaecffdf49b54af148993f4db46b
units: set NoNewPrivileges= for all long-running services

Previously, setting this option by default was problematic due to
SELinux (as this would also prohibit the transition from PID1's label to
the service's label). However, this restriction has since been lifted,
hence let's start making use of this universally in our services.

On SELinux system this change should be synchronized with a policy
update that ensures that NNP-ful transitions from init_t to service
labels is permitted.

Fixes: #1219
15 files changed:
units/systemd-coredump@.service.in
units/systemd-hostnamed.service.in
units/systemd-initctl.service.in
units/systemd-journal-gatewayd.service.in
units/systemd-journal-remote.service.in
units/systemd-journal-upload.service.in
units/systemd-journald.service.in
units/systemd-localed.service.in
units/systemd-logind.service.in
units/systemd-machined.service.in
units/systemd-networkd.service.in
units/systemd-resolved.service.in
units/systemd-rfkill.service.in
units/systemd-timedated.service.in
units/systemd-timesyncd.service.in