Open travier opened 10 months ago
Hi! FWIW I'm wondering if it is possible to add a global drop-in in ostree-enabled fedara editions to prevent other services that do not operate on ostree from accessing /sysroot
. See previous discussions at https://github.com/ostreedev/ostree/issues/3211 and https://discussion.fedoraproject.org/t/f40-change-proposal-systemd-security-hardening-system-wide/96423/31
We did not complete this effort for F40 and the global change has been pushed to F41.
For the following Fedora 40 change, we should take a look at all our systemd units and make sure they are as hardened as possible: https://fedoraproject.org/wiki/Changes/SystemdSecurityHardening
List of units to look at: