Re: systemd 230 change - KillUserProcesses defaults to yes

2016-05-30 Thread Marcelo Ricardo Leitner
Em 30-05-2016 07:56, Miroslav Suchý escreveu: Dne 28.5.2016 v 05:11 Ben Rosser napsal(a): I agree; just because the change happened upstream in systemd doesn't mean that this shouldn't be evaluated in Fedora itself before being turned on by default. This absolutely seems like the kind of thing

Phoronix article, some performance drawbacks F20

2014-05-23 Thread Marcelo Ricardo Leitner
Hi, I'm willing to run some tests but wanted to know if anyone is already looking into the bad hits we got at http://www.phoronix.com/scan.php?page=article&item=fedora_20_funky&num=1 ? I find it curious that P-state alone is to be blamed even for cpu-intensive tasks, where I would expect it

Re: We want to stop systemd from being added to docker images, because of rpm requiring systemctl.

2014-04-30 Thread Marcelo Ricardo Leitner
Em 30-04-2014 07:57, Lennart Poettering escreveu: On Tue, 29.04.14 15:36, Marcelo Ricardo Leitner (marcelo.leit...@gmail.com) wrote: Em 29-04-2014 12:27, Lennart Poettering escreveu: On Tue, 29.04.14 10:37, Daniel J Walsh (dwa...@redhat.com) wrote: On 04/29/2014 06:33 AM, Lennart

Re: We want to stop systemd from being added to docker images, because of rpm requiring systemctl.

2014-04-29 Thread Marcelo Ricardo Leitner
Em 29-04-2014 18:27, Martin Langhoff escreveu: On Tue, Apr 29, 2014 at 5:12 PM, Reindl Harald mailto:h.rei...@thelounge.net>> wrote: defense in depth means limit the attack surface as much as you can As folks are trying to point out to you, these principles are well understood in this grou

Re: We want to stop systemd from being added to docker images, because of rpm requiring systemctl.

2014-04-29 Thread Marcelo Ricardo Leitner
Em 29-04-2014 17:04, Andrew Lutomirski escreveu: On Tue, Apr 29, 2014 at 12:48 PM, Reindl Harald wrote: Am 29.04.2014 21:36, schrieb Andrew Lutomirski: On Tue, Apr 29, 2014 at 12:33 PM, Reindl Harald wrote: simple example: * binary XYZ is vulerable for privilege escalation This makes no

Re: We want to stop systemd from being added to docker images, because of rpm requiring systemctl.

2014-04-29 Thread Marcelo Ricardo Leitner
Em 29-04-2014 12:27, Lennart Poettering escreveu: On Tue, 29.04.14 10:37, Daniel J Walsh (dwa...@redhat.com) wrote: On 04/29/2014 06:33 AM, Lennart Poettering wrote: On Mon, 28.04.14 17:01, Daniel J Walsh (dwa...@redhat.com) wrote: The problem is lots of services require systemd because th

Re: default local DNS failover solution needed, nscd?

2014-04-28 Thread Marcelo Ricardo Leitner
Em 28-04-2014 11:14, Paul Wouters escreveu: On Mon, 28 Apr 2014, Marcelo Ricardo Leitner wrote: Speaking of which, I am not sure how dnsmasq plays with DNSSEC and/or failover, but NetworkManager already has a config option (/etc/NetworkManager/NetworkManager.conf, dns=dnsmasq) that makes it

Re: default local DNS failover solution needed, nscd?

2014-04-28 Thread Marcelo Ricardo Leitner
Em 28-04-2014 02:39, P J P escreveu: Hi, (sorry for the delayed response, I was away past few days) 2014-04-26 0:51 GMT+02:00 Chuck Anderson wrote: Main goal is to have local DNSSEC-validating resolver. I, as the OP, did not intend that as the goal, although I have no problem with that a