1 |
On Thu, 2020-11-26 at 17:45 -0500, Michael Orlitzky wrote: |
2 |
> On 11/26/20 5:37 PM, Peter Stuge wrote: |
3 |
> > Georgy Yakovlev wrote: |
4 |
> > > I'll be switching default tmpfiles provider to sys-apps/systemd- |
5 |
> > > tmpfiles |
6 |
> > > by the end of the week by updating virtual/tmpfiles ebuild. |
7 |
> > |
8 |
> > Michael Orlitzky wrote: |
9 |
> > > Corollary: the tmpfiles.d specification can only be implemented |
10 |
> > > (safely) |
11 |
> > > on Linux after all. |
12 |
> > |
13 |
> > So should virtual/tmpfiles differentiate based on system? |
14 |
> > |
15 |
> |
16 |
> There's no scenario where opentmpfiles is preferable. |
17 |
> |
18 |
> systemd-tmpfiles with the fs.protected_hardlinks=1 sysctl is secure on |
19 |
> Linux. On other kernels, you're out of luck -- none of the options are |
20 |
> secure. Securing the service manager on other kernels would require |
21 |
> dropping tmpfiles entirely, and major changes to OpenRC. |
22 |
> |
23 |
|
24 |
...which is mostly a theoretical exercise, because we only support Linux |
25 |
anyways. |