aboutsummaryrefslogtreecommitdiff
path: root/NEWS
diff options
context:
space:
mode:
authorLennart Poettering <lennart@poettering.net>2018-04-19 16:51:04 +0200
committerLennart Poettering <lennart@poettering.net>2018-06-14 17:44:20 +0200
commite01d9e2193ad4699a0507fc631613b5666d4d897 (patch)
tree0efa03061c706fd3a57f8a41b714971d5c0c1bc1 /NEWS
parentportable: add SystemCallFilter=@system-service to the three main portable ser... (diff)
downloadsystemd-e01d9e2193ad4699a0507fc631613b5666d4d897.tar.gz
systemd-e01d9e2193ad4699a0507fc631613b5666d4d897.tar.bz2
systemd-e01d9e2193ad4699a0507fc631613b5666d4d897.zip
update NEWS
Diffstat (limited to 'NEWS')
-rw-r--r--NEWS9
1 files changed, 9 insertions, 0 deletions
diff --git a/NEWS b/NEWS
index cca6692c4..03fe0eca8 100644
--- a/NEWS
+++ b/NEWS
@@ -46,6 +46,15 @@ CHANGES WITH 239 in spe:
both runtime and persistent enablement/masking, i.e. it will remove
any relevant symlinks both in /run and /etc.
+ * Note that all long-running system services shipped with systemd will
+ now default to a system call whitelist (rather than a blacklist, as
+ before). In particular, systemd-udevd will now enforce one too. For
+ most cases this should be safe, however downstream distributions
+ which disabled sandboxing of systemd-udevd (specifically the
+ MountFlags= setting), might want to disable this security feature
+ too, as the default whitelisting will prohibit all mount, swap,
+ reboot and clock changing operations from udev rules.
+
* sd-boot acquired new loader configuration settings to optionally turn
off Windows and MacOS boot partition discovery as well as
reboot-into-firmware menu items. It is also able to pick a better