Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units

2022-08-26 Thread Rich Freeman
On Fri, Aug 26, 2022 at 4:57 AM Florian Schmaus wrote: > > While then can not be modified, settings made in /usr/lib/systemd/system > can be overridden by the sysadmin by placing a file in /etc/systemd/system. > > I am not aware of a reason why a package manger should install systemd > configurati

Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units

2022-08-26 Thread Florian Schmaus
On 25/08/2022 17.03, Michał Górny wrote: On Thu, 2022-08-25 at 16:06 +0200, Florian Schmaus wrote: On 25/08/2022 15.25, Kenton Groombridge wrote: I think the best way to address this is to have packages ship unit override files instead of unit files themselves which enable these options. For ex

Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units

2022-08-25 Thread Mike Gilbert
On Thu, Aug 25, 2022 at 1:41 PM Kenton Groombridge wrote: > > On 22/08/25 01:04PM, Mike Gilbert wrote: > > We could introduce a new function to install distro-specific overrides > > in [/usr]/lib/systemd/system. > > > > I think that's a good idea. systemd_{new,do}serviceconf maybe? > > As I unders

Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units

2022-08-25 Thread Kenton Groombridge
On 22/08/25 01:04PM, Mike Gilbert wrote: > We could introduce a new function to install distro-specific overrides > in [/usr]/lib/systemd/system. > I think that's a good idea. systemd_{new,do}serviceconf maybe? As I understand it these should go to /usr/lib/[...]. signature.asc Description: PG

Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units

2022-08-25 Thread Mike Gilbert
On Thu, Aug 25, 2022 at 10:29 AM Kenton Groombridge wrote: > > On 22/08/25 04:06PM, Florian Schmaus wrote: > > Wouldn't the proper place for overrides installed by a distributions package > > manager be > > > > /usr/lib/systemd/system/miniflux.service.d/gentoo.conf > > > > Yes... I was wondering t

Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units

2022-08-25 Thread Michał Górny
On Thu, 2022-08-25 at 16:06 +0200, Florian Schmaus wrote: > On 25/08/2022 15.25, Kenton Groombridge wrote: > > I think the best way to address this is to have packages ship unit override > > files instead of unit files themselves which enable these options. For > > example, > > instead of Gentoo s

Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units

2022-08-25 Thread Kenton Groombridge
On 22/08/25 04:06PM, Florian Schmaus wrote: > Wouldn't the proper place for overrides installed by a distributions package > manager be > > /usr/lib/systemd/system/miniflux.service.d/gentoo.conf > Yes... I was wondering that too. Currently systemd_install_serviced installs to /etc/systemd/system

Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units

2022-08-25 Thread Florian Schmaus
On 25/08/2022 15.25, Kenton Groombridge wrote: I think the best way to address this is to have packages ship unit override files instead of unit files themselves which enable these options. For example, instead of Gentoo shipping a modified miniflux.service unit file, we can instead install a fil

Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units

2022-08-25 Thread Kenton Groombridge
On 22/08/22 03:42PM, Mike Gilbert wrote: > On Mon, Aug 22, 2022 at 2:10 PM Kenton Groombridge wrote: > > What do you think? > > I am concerned that people will start mass filing bugs with > suggestions without fully understanding them or without testing them > thoroughly. Please don't do that. >

Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units

2022-08-23 Thread Florian Schmaus
On 22/08/2022 20.10, Kenton Groombridge wrote: Hi everyone, I noticed that there are many systemd units which are shipped by various packages which could be hardened, some further than they are currently and some that could use some hardening in general. Yes, please. Nevertheless, as others ha

Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units

2022-08-22 Thread Mike Gilbert
On Mon, Aug 22, 2022 at 2:10 PM Kenton Groombridge wrote: > What do you think? I am concerned that people will start mass filing bugs with suggestions without fully understanding them or without testing them thoroughly. Please don't do that. Also, ideally we would not need to provide systemd uni

Re: [gentoo-dev] [RFC] Encouraging using hardening options in systemd units

2022-08-22 Thread John Helmert III
On Mon, Aug 22, 2022 at 02:10:47PM -0400, Kenton Groombridge wrote: > Hi everyone, > > I noticed that there are many systemd units which are shipped by various > packages which could be hardened, some further than they are currently and > some > that could use some hardening in general. > > For

[gentoo-dev] [RFC] Encouraging using hardening options in systemd units

2022-08-22 Thread Kenton Groombridge
Hi everyone, I noticed that there are many systemd units which are shipped by various packages which could be hardened, some further than they are currently and some that could use some hardening in general. For those who are unaware, systemd units support many options which can be used to restri