1 |
I'm not sure about how systemd behaves. If a proper GID can be configured, |
2 |
it can provide a solution for the grsec PROC vs systemd issue... |
3 |
-- |
4 |
dr Tóth Attila, Radiológus, 06-20-825-8057 |
5 |
Attila Toth MD, Radiologist, +36-20-825-8057 |
6 |
|
7 |
2013.December 17.(K) 08:29 időpontban Sven Vermeulen ezt írta: |
8 |
> On Dec 17, 2013 12:56 AM, Tóth Attila <atoth@××××××××××.hu> wrote: |
9 |
>> |
10 |
>> It turns out systemd is not compatible with CONFIG_GRKERNSEC_PROC. It |
11 |
>> has |
12 |
>> been reported as freedesktop bug #65575. Of course if there would be a |
13 |
>> specific group under which systemd performs its proc related activities, |
14 |
>> that could be configured as the exception GID, but I can hardly imagine |
15 |
>> that it is the case. |
16 |
> |
17 |
> I thought one of the principles of systemd is that it keeps running |
18 |
> (daemonized) and you communicate with it over sockets. Are you sure |
19 |
> systemd |
20 |
> doesn't run with a fixed GID? Probably even the root GID. |
21 |
> |
22 |
> Wkr, |
23 |
> Sven |
24 |
> |