mirror of
https://github.com/systemd/systemd
synced 2024-11-05 18:25:39 +00:00
journal: make gatewayd run under its own user ID
This commit is contained in:
parent
37c0e8f35e
commit
37495eede9
2 changed files with 14 additions and 5 deletions
16
README
16
README
|
@ -101,11 +101,12 @@ REQUIREMENTS:
|
|||
pass the same DESTDIR to 'make sphinx-html' invocation.
|
||||
|
||||
USERS AND GROUPS:
|
||||
Default udev rules use the following standard system group names,\
|
||||
which need to be resolvable by getgrnam() at any time, even in the
|
||||
very early boot stages, where no other databases and network is
|
||||
available:
|
||||
tty, dialout, kmem, video, audio, lp, floppy, cdrom, tape, disk
|
||||
Default udev rules use the following standard system group
|
||||
names, which need to be resolvable by getgrnam() at any time,
|
||||
even in the very early boot stages, where no other databases
|
||||
and network are available:
|
||||
|
||||
tty, dialout, kmem, video, audio, lp, floppy, cdrom, tape, disk
|
||||
|
||||
During runtime the journal daemon requires the
|
||||
"system-journal" system group to exist. New journal files will
|
||||
|
@ -119,6 +120,11 @@ USERS AND GROUPS:
|
|||
|
||||
# setfacl -nm g:wheel:rx,d:g:wheel:rx,g:adm:rx,d:g:adm:rx /var/log/journal/
|
||||
|
||||
The journal gateway daemon requires the
|
||||
"system-journal-gateway" system user and group to
|
||||
exist. During execution this network facing service will drop
|
||||
privileges and assume this uid/gid for security reasons.
|
||||
|
||||
WARNINGS:
|
||||
systemd will warn you during boot if /etc/mtab is not a
|
||||
symlink to /proc/mounts. Please ensure that /etc/mtab is a
|
||||
|
|
|
@ -11,6 +11,9 @@ Requires=systemd-journal-gatewayd.socket
|
|||
|
||||
[Service]
|
||||
ExecStart=@rootlibexecdir@/systemd-journal-gatewayd
|
||||
User=systemd-journal-gateway
|
||||
Group=systemd-journal-gateway
|
||||
SupplementaryGroups=systemd-journal
|
||||
|
||||
[Install]
|
||||
Also=systemd-journal-gatewayd.socket
|
||||
|
|
Loading…
Reference in a new issue