[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#771630: anacron: Please add ProtectSystem=yes to systemd service file



Control: tag -1 + wontfix

I guess we cannot do that for the same reason as Bug #771629.

--
Thanks,
Boyuan Yang

On Sun, 30 Nov 2014 22:51:28 -0500 Micah Anderson <micah@debian.org> wrote:
> Package: anacron
> Version: 2.3-22
> Severity: wishlist
> 
> Dear Maintainer,
> 
> *** Reporter, please consider answering these questions, where appropriate
***
> 
>    * What led up to the situation?
>    * What exactly did you do (or not do) that was effective (or
>      ineffective)?
>    * What was the outcome of this action?
>    * What outcome did you expect instead?
> 
> *** End of the template - remove these template lines ***
> 
> 
> Hello,
> 
> If you add the option ProtectSystem=yes to the service file, then the
> daemon will not have the ability to write to /usr.
> 
> There is no reason why it needs to write there, so enabling this
> option should not cause any problems.
> 
> This option is one of the systemd security features for systemd
> service files that was detailed in a talk[0] given by Lennart which
> details various security features you can enable in your package's
> service files.
> 
> micah
> 
> [0] 
http://ftp.nluug.nl/video/nluug/2014-11-20_nj14/zaal-2/5_Lennart_Poettering_-_Systemd.webm
> 
> -- System Information:
> Debian Release: jessie/sid
>   APT prefers unstable
>   APT policy: (500, 'unstable')
> Architecture: amd64 (x86_64)
> Foreign Architectures: i386
> 
> Kernel: Linux 3.16.0-4-amd64 (SMP w/8 CPU cores)
> Locale: LANG=en_US.utf8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
> Shell: /bin/sh linked to /bin/dash
> 
> Versions of packages anacron depends on:
> ii  debianutils          4.4+b1
> ii  init-system-helpers  1.22
> ii  libc6                2.19-13
> ii  lsb-base             4.1+Debian13+nmu1
> 
> Versions of packages anacron recommends:
> ii  cron [cron-daemon]           3.0pl1-127
> ii  rsyslog [system-log-daemon]  8.4.2-1
> 
> Versions of packages anacron suggests:
> ii  postfix [mail-transport-agent]  2.11.3-1
> ii  powermgmt-base                  1.31+nmu1
> 
> -- no debconf information

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: