Re: [systemd-devel] systemd's connections to /run/systemd/private ?

2019-07-11 Thread Zbigniew Jędrzejewski-Szmek
On Thu, Jul 11, 2019 at 10:08:43AM -0400, Brian Reichert wrote: > On Wed, Jul 10, 2019 at 10:44:14PM +, Zbigniew J??drzejewski-Szmek wrote: > > That's ancient... 228 was released almost four years ago. > > That's the joy of using a commercial Linux distribution; they tend > to be conservative

Re: [systemd-devel] Delegate v1 cgroup controller permissions

2019-07-11 Thread Lennart Poettering
On Do, 11.07.19 09:57, Michal Koutný (mkou...@suse.com) wrote: > On Thu, Jun 20, 2019 at 02:19:34PM +0200, Lennart Poettering > wrote: > > Sorry, but there is not, it's not safe, as documented. > > The doc [1] says: > > Think twice before delegating cgroup v1 controllers to less privileged > >

Re: [systemd-devel] systemd's connections to /run/systemd/private ?

2019-07-11 Thread Brian Reichert
On Wed, Jul 10, 2019 at 10:44:14PM +, Zbigniew J??drzejewski-Szmek wrote: > That's ancient... 228 was released almost four years ago. That's the joy of using a commercial Linux distribution; they tend to be conservative about updates. SLES may very well have backported fixes to the packaged

Re: [systemd-devel] Delegate v1 cgroup controller permissions

2019-07-11 Thread Michal Koutný
On Thu, Jun 20, 2019 at 02:19:34PM +0200, Lennart Poettering wrote: > Sorry, but there is not, it's not safe, as documented. The doc [1] says: > Think twice before delegating cgroup v1 controllers to less privileged > containers. It’s not safe, you basically allow your containers to > freeze