summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLennart Poettering <lennart@poettering.net>2024-10-23 22:22:54 +0200
committerLennart Poettering <lennart@poettering.net>2024-10-29 11:00:13 +0100
commita4c0528f14257e23a8fad8855f178ef71d99978b (patch)
tree011c10e89cceb7a8bba6a05162e9775a4ccf9c56
parentsysusers: add new ! line flag for creating fully locked accounts (diff)
downloadsystemd-a4c0528f14257e23a8fad8855f178ef71d99978b.tar.xz
systemd-a4c0528f14257e23a8fad8855f178ef71d99978b.zip
sysusers.d: lock all system users defined by us
-rw-r--r--sysusers.d/basic.conf.in2
-rw-r--r--sysusers.d/systemd-coredump.conf2
-rw-r--r--sysusers.d/systemd-network.conf.in2
-rw-r--r--sysusers.d/systemd-oom.conf2
-rw-r--r--sysusers.d/systemd-remote.conf2
-rw-r--r--sysusers.d/systemd-resolve.conf.in2
-rw-r--r--sysusers.d/systemd-timesync.conf.in2
7 files changed, 7 insertions, 7 deletions
diff --git a/sysusers.d/basic.conf.in b/sysusers.d/basic.conf.in
index 0aec080a4c..992af346ca 100644
--- a/sysusers.d/basic.conf.in
+++ b/sysusers.d/basic.conf.in
@@ -11,7 +11,7 @@ u root 0:0 "Super User" /root
# The nobody user/group for NFS file systems
g {{NOBODY_GROUP_NAME}} 65534 - -
-u {{NOBODY_USER_NAME }} 65534:65534 "Kernel Overflow User" -
+u! {{NOBODY_USER_NAME }} 65534:65534 "Kernel Overflow User" -
# Administrator group: can *see* more than normal users
g adm {{ADM_GID }} - -
diff --git a/sysusers.d/systemd-coredump.conf b/sysusers.d/systemd-coredump.conf
index c4ff003bd6..2ab8a41b9d 100644
--- a/sysusers.d/systemd-coredump.conf
+++ b/sysusers.d/systemd-coredump.conf
@@ -5,4 +5,4 @@
# the Free Software Foundation; either version 2.1 of the License, or
# (at your option) any later version.
-u systemd-coredump - "systemd Core Dumper"
+u! systemd-coredump - "systemd Core Dumper"
diff --git a/sysusers.d/systemd-network.conf.in b/sysusers.d/systemd-network.conf.in
index 7c64a4681f..fc04827efd 100644
--- a/sysusers.d/systemd-network.conf.in
+++ b/sysusers.d/systemd-network.conf.in
@@ -5,4 +5,4 @@
# the Free Software Foundation; either version 2.1 of the License, or
# (at your option) any later version.
-u systemd-network {{SYSTEMD_NETWORK_UID}} "systemd Network Management"
+u! systemd-network {{SYSTEMD_NETWORK_UID}} "systemd Network Management"
diff --git a/sysusers.d/systemd-oom.conf b/sysusers.d/systemd-oom.conf
index 27e571feb5..1ce3d23b6b 100644
--- a/sysusers.d/systemd-oom.conf
+++ b/sysusers.d/systemd-oom.conf
@@ -5,4 +5,4 @@
# the Free Software Foundation; either version 2.1 of the License, or
# (at your option) any later version.
-u systemd-oom - "systemd Userspace OOM Killer"
+u! systemd-oom - "systemd Userspace OOM Killer"
diff --git a/sysusers.d/systemd-remote.conf b/sysusers.d/systemd-remote.conf
index ca20c24896..796850c9e6 100644
--- a/sysusers.d/systemd-remote.conf
+++ b/sysusers.d/systemd-remote.conf
@@ -5,4 +5,4 @@
# the Free Software Foundation; either version 2.1 of the License, or
# (at your option) any later version.
-u systemd-journal-remote - "systemd Journal Remote"
+u! systemd-journal-remote - "systemd Journal Remote"
diff --git a/sysusers.d/systemd-resolve.conf.in b/sysusers.d/systemd-resolve.conf.in
index 9f02ef94e6..e385070c45 100644
--- a/sysusers.d/systemd-resolve.conf.in
+++ b/sysusers.d/systemd-resolve.conf.in
@@ -5,4 +5,4 @@
# the Free Software Foundation; either version 2.1 of the License, or
# (at your option) any later version.
-u systemd-resolve {{SYSTEMD_RESOLVE_UID}} "systemd Resolver"
+u! systemd-resolve {{SYSTEMD_RESOLVE_UID}} "systemd Resolver"
diff --git a/sysusers.d/systemd-timesync.conf.in b/sysusers.d/systemd-timesync.conf.in
index e50f025416..7b9fb3d8d9 100644
--- a/sysusers.d/systemd-timesync.conf.in
+++ b/sysusers.d/systemd-timesync.conf.in
@@ -5,4 +5,4 @@
# the Free Software Foundation; either version 2.1 of the License, or
# (at your option) any later version.
-u systemd-timesync {{SYSTEMD_TIMESYNC_UID}} "systemd Time Synchronization"
+u! systemd-timesync {{SYSTEMD_TIMESYNC_UID}} "systemd Time Synchronization"