Skip to content

Improve systemd-analyze security a bit and other assorted bits - #16640

Merged
poettering merged 7 commits into
systemd:masterfrom
keszybz:various-patches
Aug 19, 2020
Merged

poettering merged 7 commits into
systemd:masterfrom
keszybz:various-patches

Conversation

@keszybz

@keszybz keszybz commented Aug 1, 2020

Copy link
Copy Markdown
Member

No description provided.

keszybz added 2 commits August 1, 2020 11:54
I was reading a summary of changes on Phoronix, and (while not incorrect)
those two points were rather misleading.
Comment thread src/analyze/analyze-security.c Outdated
Comment thread src/analyze/analyze-security.c Outdated

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why the newline?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The assert makes sure that the *f assignment is OK.
The two variable declarations below are a separate thing.

@poettering poettering added the reviewed/needs-rework 🔨 PR has been reviewed and needs another round of reworks label Aug 5, 2020
@poettering poettering linked an issue Aug 6, 2020 that may be closed by this pull request
This information was already available in the debug output, but I think it
is good to include it in the message in the table. This makes it easier to wrap
one's head around the allowlist/denylist filtering.
This comes up occasionally with new users. The phrase "Logs begin ..." is
ambiguous because it can be taken to mean the logs being displayed or all logs
(the intended meaning). Let's rephrase this as "Journal begins ..." to make
this clearer.
Every time I was using this function I had to check whether "newline"
means that newlines are good or bad.
@keszybz keszybz removed the reviewed/needs-rework 🔨 PR has been reviewed and needs another round of reworks label Aug 17, 2020
@keszybz

keszybz commented Aug 17, 2020

Copy link
Copy Markdown
Member Author

Updated to always initialize ret_offending_syscall, no other changes.

@poettering
poettering merged commit b0073a0 into systemd:master Aug 19, 2020
@keszybz
keszybz deleted the various-patches branch August 19, 2020 15:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

systemd-analyze: badness calculation confused for syscall denylists

2 participants