Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Enhancement] Hardening the systemd service #596

Open
ptr1337 opened this issue Sep 1, 2024 · 2 comments
Open

[Enhancement] Hardening the systemd service #596

ptr1337 opened this issue Sep 1, 2024 · 2 comments

Comments

@ptr1337
Copy link
Contributor

ptr1337 commented Sep 1, 2024

The systemd service does not use any hardening options currently, but we should work them out, since its pretty important if we want to put this default enabled at distributions.

Fedora is also working on hardening their service, see here:
https://fedoraproject.org/wiki/Changes/SystemdSecurityHardening#Detailed_Description

Many of these can be also applied for the scx.service

@sirlucjan
Copy link
Contributor

Good idea, we have brought it up before and at the next office hours we can bring it up again

@Dietr1ch
Copy link

Dietr1ch commented Sep 2, 2024

BTW, when touching the systemd config it might be worth to set up the exec properties like Nice=

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants