Proposing Fedora Feature for private /tmp and /var/tmp for all systemd services in Fedora 17.

Daniel J Walsh dwalsh at redhat.com
Mon Nov 7 20:47:06 UTC 2011


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 11/07/2011 03:44 PM, Chris Adams wrote:
> Once upon a time, Daniel J Walsh <dwalsh at redhat.com> said:
>> I know I just opened a couple of other features on Fedora 17.  I
>> just wanted to open discussion on this about what would be the
>> best way to do this.
>> 
>> * Maybe a bad idea.  Since admins might get confused by different
>> /tmp(s).
> 
> Hmm, one question: is it possible for root to see these alternate
> tmps?


I think this is a question for lennart, I am not sure how he sets them
up.  If I was setting them up, I would probably set them up by default
under /run/SERVICE/tmp and bind mount over /tmp or something like
that.  And I would figure the root user could see them.  If he is only
mounting as tmpfs then I don't think the admin could easily get into
the namespaces to see them.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk64Q8oACgkQrlYvE4MpobPE8QCfRyK0SPs7x2QI3/2bR8634MZZ
GIcAn2x86uit23DNbnleiZpK3HyO6CQv
=io0J
-----END PGP SIGNATURE-----


More information about the devel mailing list