1 |
It turns out systemd is not compatible with CONFIG_GRKERNSEC_PROC. It has |
2 |
been reported as freedesktop bug #65575. Of course if there would be a |
3 |
specific group under which systemd performs its proc related activities, |
4 |
that could be configured as the exception GID, but I can hardly imagine |
5 |
that it is the case. Gentoo systemd wiki doesn't mention this point, |
6 |
otherwise important for hardened users. Systemd dev stands his ground and |
7 |
puts the period: nothing can be expected until grsecurity hits mainline. |
8 |
That will obviously not happen. I understand the dev having no intentions |
9 |
to support out-of-mainline features. Altering proc access significantly. |
10 |
|
11 |
Any of you have a workaround for systemd with grsec without completely |
12 |
loosing proc restrictions? |
13 |
|
14 |
I'm trying real hard to be a shepherd. But this time I feel the urge - |
15 |
again - to purge the remnants of the once so shiny GNOME from my systems. |
16 |
|
17 |
Any thoughts on this? Or rather a grsec proc config workaround? |
18 |
|
19 |
Thx: |
20 |
Dw. |
21 |
-- |
22 |
dr Tóth Attila, Radiológus, 06-20-825-8057 |
23 |
Attila Toth MD, Radiologist, +36-20-825-8057 |