]> git.ipfire.org Git - thirdparty/systemd.git/commitdiff
NEWS: add a comment about udev's MemoryDenyWriteExecute= setting (#5414)
authorLennart Poettering <lennart@poettering.net>
Wed, 22 Feb 2017 00:36:12 +0000 (01:36 +0100)
committerZbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl>
Wed, 22 Feb 2017 00:36:12 +0000 (19:36 -0500)
Apparently if people are adventurous enought to run Go programs in udev
rules they might run into problems with MemoryDenyWriteExecute=.

I am pretty sure the best way out is for the toolchain generating
programs incompatible with W^X to be fixed, but this still deserves
documentation.

This was forgotten for the 232 release, hence add it now, retroactively.

See: #5400

NEWS

diff --git a/NEWS b/NEWS
index 954a83a0b6eeae6e310530ee0a788a704254a68b..a3b3fef62768ff9c0f677d6dd8c11cd2dcf3f160 100644 (file)
--- a/NEWS
+++ b/NEWS
@@ -357,6 +357,13 @@ CHANGES WITH 233 in spe
 
 CHANGES WITH 232:
 
+        * udev now runs with MemoryDenyWriteExecute=, RestrictRealtime= and
+          RestrictAddressFamilies= enabled. These sandboxing options should
+          generally be compatible with the various external udev call-out
+          binaries we are aware of, however there may be exceptions, in
+          particular when exotic languages for these call-outs are used. In
+          this case, consider turning off these settings locally.
+
         * The new RemoveIPC= option can be used to remove IPC objects owned by
           the user or group of a service when that service exits.