mirror of
https://github.com/systemd/systemd.git
synced 2026-07-20 06:20:28 +00:00
This adds a new ProtectSystem= setting that mirrors the option of the same of services, but in a more restrictive way. If enabled will remount /usr/ to read-only, very early at boot. Takes a special value "auto" (which is the default) which is equivalent to true in the initrd, and false otherwise. Unlike the per-service option we don't support full/strict modes, but the door is open to eventually support that too if it makes sense. It's not entirely trivial though as we have very little mounted this early, and hence the mechanism might not apply 1:1. Hence in this PR is a conservative first step. My primary goal with this is to lock down initrds a bit, since they conceptually are mostly immutable, but they are unpacked into a mutable tmpfs. let's tighten the screws a bit on that, and at least make /usr/ immutable. This is particularly nice on USIs (i.e. Unified System Images, that pack a whole OS into a UKI without transitioning out of it), such as diskomator.
85 lines
2.4 KiB
Plaintext
85 lines
2.4 KiB
Plaintext
# This file is part of systemd.
|
|
#
|
|
# systemd is free software; you can redistribute it and/or modify it under the
|
|
# terms of the GNU Lesser General Public License as published by the Free
|
|
# Software Foundation; either version 2.1 of the License, or (at your option)
|
|
# any later version.
|
|
#
|
|
# Entries in this file show the compile time defaults. Local configuration
|
|
# should be created by either modifying this file (or a copy of it placed in
|
|
# /etc/ if the original file is shipped in /usr/), or by creating "drop-ins" in
|
|
# /etc/systemd/system.conf.d/ directory. The latter is generally recommended.
|
|
# Defaults can be restored by simply deleting the main configuration file and
|
|
# all drop-ins located in /etc/.
|
|
#
|
|
# Use 'systemd-analyze cat-config systemd/system.conf' to display the full config.
|
|
#
|
|
# See systemd-system.conf(5) for details.
|
|
|
|
[Manager]
|
|
#LogLevel=info
|
|
#LogTarget=journal-or-kmsg
|
|
#LogColor=yes
|
|
#LogLocation=no
|
|
#LogTime=no
|
|
#DumpCore=yes
|
|
#ShowStatus=yes
|
|
#CrashChangeVT=no
|
|
#CrashShell=no
|
|
#CrashReboot=no
|
|
#CtrlAltDelBurstAction=reboot-force
|
|
#CPUAffinity=
|
|
#NUMAPolicy=default
|
|
#NUMAMask=
|
|
#RuntimeWatchdogSec=off
|
|
#RuntimeWatchdogPreSec=off
|
|
#RuntimeWatchdogPreGovernor=
|
|
#RebootWatchdogSec=10min
|
|
#KExecWatchdogSec=off
|
|
#WatchdogDevice=
|
|
#CapabilityBoundingSet=
|
|
#NoNewPrivileges=no
|
|
#ProtectSystem=auto
|
|
#SystemCallArchitectures=
|
|
#TimerSlackNSec=
|
|
#StatusUnitFormat={{STATUS_UNIT_FORMAT_DEFAULT_STR}}
|
|
#DefaultTimerAccuracySec=1min
|
|
#DefaultStandardOutput=journal
|
|
#DefaultStandardError=inherit
|
|
#DefaultTimeoutStartSec={{DEFAULT_TIMEOUT_SEC}}s
|
|
#DefaultTimeoutStopSec={{DEFAULT_TIMEOUT_SEC}}s
|
|
#DefaultTimeoutAbortSec=
|
|
#DefaultDeviceTimeoutSec={{DEFAULT_TIMEOUT_SEC}}s
|
|
#DefaultRestartSec=100ms
|
|
#DefaultStartLimitIntervalSec=10s
|
|
#DefaultStartLimitBurst=5
|
|
#DefaultEnvironment=
|
|
#DefaultCPUAccounting=yes
|
|
#DefaultIOAccounting=no
|
|
#DefaultIPAccounting=no
|
|
#DefaultMemoryAccounting={{ 'yes' if MEMORY_ACCOUNTING_DEFAULT else 'no' }}
|
|
#DefaultTasksAccounting=yes
|
|
#DefaultTasksMax=15%
|
|
#DefaultLimitCPU=
|
|
#DefaultLimitFSIZE=
|
|
#DefaultLimitDATA=
|
|
#DefaultLimitSTACK=
|
|
#DefaultLimitCORE=
|
|
#DefaultLimitRSS=
|
|
#DefaultLimitNOFILE=1024:{{HIGH_RLIMIT_NOFILE}}
|
|
#DefaultLimitAS=
|
|
#DefaultLimitNPROC=
|
|
#DefaultLimitMEMLOCK=8M
|
|
#DefaultLimitLOCKS=
|
|
#DefaultLimitSIGPENDING=
|
|
#DefaultLimitMSGQUEUE=
|
|
#DefaultLimitNICE=
|
|
#DefaultLimitRTPRIO=
|
|
#DefaultLimitRTTIME=
|
|
#DefaultMemoryPressureThresholdSec=200ms
|
|
#DefaultMemoryPressureWatch=auto
|
|
#DefaultOOMPolicy=stop
|
|
#DefaultSmackProcessLabel=
|
|
#ReloadLimitIntervalSec=
|
|
#ReloadLimitBurst=
|