Gentoo Archives: gentoo-dev

From: "Michał Górny" <mgorny@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units
Date: Thu, 25 Aug 2022 15:03:59
Message-Id: 770d1c9067de0de211abf4965259ada9bf7e2624.camel@gentoo.org
In Reply to: Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units by Florian Schmaus
1 On Thu, 2022-08-25 at 16:06 +0200, Florian Schmaus wrote:
2 > On 25/08/2022 15.25, Kenton Groombridge wrote:
3 > > I think the best way to address this is to have packages ship unit override
4 > > files instead of unit files themselves which enable these options. For example,
5 > > instead of Gentoo shipping a modified miniflux.service unit file, we can instead
6 > > install a file to /etc/system/miniflux.service.d/00gentoo.conf using the
7 > > existing systemd_install_serviced helper in systemd.eclass which enables these
8 > > options.
9 >
10 > Wouldn't the proper place for overrides installed by a distributions
11 > package manager be
12 >
13 > /usr/lib/systemd/system/miniflux.service.d/gentoo.conf
14 >
15
16 These files are meant to be modifiable by the sysadmin, so they don't
17 belong in /usr.
18
19 --
20 Best regards,
21 Michał Górny

Replies