Gentoo Archives: gentoo-dev

From: David Seifert <soap@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] PSA: switching default tmpfiles virtual provider
Date: Thu, 26 Nov 2020 22:58:46
Message-Id: 55d5be36f28a11340517ab0827d2a8da7b83b420.camel@gentoo.org
In Reply to: Re: [gentoo-dev] PSA: switching default tmpfiles virtual provider by Michael Orlitzky
1 On Thu, 2020-11-26 at 17:45 -0500, Michael Orlitzky wrote:
2 > On 11/26/20 5:37 PM, Peter Stuge wrote:
3 > > Georgy Yakovlev wrote:
4 > > > I'll be switching default tmpfiles provider to sys-apps/systemd-
5 > > > tmpfiles
6 > > > by the end of the week by updating virtual/tmpfiles ebuild.
7 > >
8 > > Michael Orlitzky wrote:
9 > > > Corollary: the tmpfiles.d specification can only be implemented
10 > > > (safely)
11 > > > on Linux after all.
12 > >
13 > > So should virtual/tmpfiles differentiate based on system?
14 > >
15 >
16 > There's no scenario where opentmpfiles is preferable.
17 >
18 > systemd-tmpfiles with the fs.protected_hardlinks=1 sysctl is secure on
19 > Linux. On other kernels, you're out of luck -- none of the options are
20 > secure. Securing the service manager on other kernels would require
21 > dropping tmpfiles entirely, and major changes to OpenRC.
22 >
23
24 ...which is mostly a theoretical exercise, because we only support Linux
25 anyways.