]> git.ipfire.org Git - thirdparty/systemd.git/commitdiff
units: use PrivateTmp=disconnected instead of 'yes' if DefaultDependencies=no
authorLuca Boccassi <luca.boccassi@gmail.com>
Thu, 12 Dec 2024 11:48:52 +0000 (11:48 +0000)
committerMike Yuan <me@yhndnzj.com>
Thu, 12 Dec 2024 21:48:04 +0000 (22:48 +0100)
Avoids subtle race conditions such as the one described at
#35582.

Fixes #35582

units/systemd-coredump@.service.in
units/systemd-oomd.service.in
units/systemd-resolved.service.in
units/systemd-timesyncd.service.in

index fa3206d07b5dfecd91a1889b86de079b6e5ec0b8..c74dc7a5a117124d49954440b3668059c5646f84 100644 (file)
@@ -26,7 +26,7 @@ NoNewPrivileges=yes
 OOMScoreAdjust=500
 PrivateDevices=yes
 PrivateNetwork=yes
-PrivateTmp=yes
+PrivateTmp=disconnected
 ProtectControlGroups=yes
 ProtectHome=read-only
 ProtectHostname=yes
index 82bd6245f83a211cf41496947308742e08ed8a4e..670d5e61408142d20793429a29f5548207c892e2 100644 (file)
@@ -37,7 +37,7 @@ MemoryLow=64M
 NoNewPrivileges=yes
 OOMScoreAdjust=-900
 PrivateDevices=yes
-PrivateTmp=yes
+PrivateTmp=disconnected
 ProtectClock=yes
 ProtectHome=yes
 ProtectHostname=yes
index 4aa0788ac4e31d7e35b17381b5ef81f97e61d22f..e181b2528ae4ca58d6373e1f3758408b0101e8f0 100644 (file)
@@ -29,7 +29,7 @@ LockPersonality=yes
 MemoryDenyWriteExecute=yes
 NoNewPrivileges=yes
 PrivateDevices=yes
-PrivateTmp=yes
+PrivateTmp=disconnected
 ProtectClock=yes
 ProtectControlGroups=yes
 ProtectHome=yes
index cf233fbffd4f2dc21146fbca4ed4481358df175c..835d6327e7aa5474988b2563d6e296ed218c2b84 100644 (file)
@@ -31,7 +31,7 @@ LockPersonality=yes
 MemoryDenyWriteExecute=yes
 NoNewPrivileges=yes
 PrivateDevices=yes
-PrivateTmp=yes
+PrivateTmp=disconnected
 ProtectProc=invisible
 ProtectControlGroups=yes
 ProtectHome=yes