Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -5,27 +5,26 @@ Subject: [PATCH 4/4] Remove unused default groups, rules and tmpfiles

Some of these groups and users are also created by filesystem
---
rules.d/50-udev-default.rules.in | 11 ---------
rules.d/50-udev-default.rules.in | 12 ----------
sysusers.d/basic.conf.in | 26 ---------------------
sysusers.d/systemd-journal.conf.in | 2 --
sysusers.d/systemd-network.conf.in | 2 --
sysusers.d/systemd-remote.conf | 2 --
sysusers.d/systemd-resolve.conf.in | 2 --
sysusers.d/systemd-timesync.conf.in | 2 --
tmpfiles.d/static-nodes-permissions.conf.in | 3 ---
8 files changed, 50 deletions(-)
7 files changed, 49 deletions(-)

diff --git a/rules.d/50-udev-default.rules.in b/rules.d/50-udev-default.rules.in
index 8fa518cd8f..23f43d0409 100644
--- a/rules.d/50-udev-default.rules.in
+++ b/rules.d/50-udev-default.rules.in
@@ -53,13 +53,8 @@ SUBSYSTEM=="dvb", GROUP="video"
@@ -53,13 +53,7 @@ SUBSYSTEM=="dvb", GROUP="video"
SUBSYSTEM=="media", GROUP="video"
SUBSYSTEM=="cec", GROUP="video"

-SUBSYSTEM=="drm", KERNEL=="renderD*", GROUP="render", MODE="{{GROUP_RENDER_MODE}}"
-SUBSYSTEM=="kfd", GROUP="render", MODE="{{GROUP_RENDER_MODE}}"
SUBSYSTEM=="accel", GROUP="render", MODE="{{GROUP_RENDER_MODE}}"
-SUBSYSTEM=="accel", GROUP="render", MODE="{{GROUP_RENDER_MODE}}"

-SUBSYSTEM=="misc", KERNEL=="sgx_enclave", GROUP="sgx", MODE="0660"
-SUBSYSTEM=="misc", KERNEL=="sgx_vepc", GROUP="sgx", MODE="0660"
Expand Down Expand Up @@ -91,16 +90,6 @@ index 992af346ca..c66181be00 100644
-
-# Default group for normal users
-g users {{USERS_GID }} - -
diff --git a/sysusers.d/systemd-journal.conf.in b/sysusers.d/systemd-journal.conf.in
index 61768b234e..5873bfab30 100644
--- a/sysusers.d/systemd-journal.conf.in
+++ b/sysusers.d/systemd-journal.conf.in
@@ -4,5 +4,3 @@
# under the terms of the GNU Lesser General Public License as published by
# the Free Software Foundation; either version 2.1 of the License, or
# (at your option) any later version.
-
-g systemd-journal {{SYSTEMD_JOURNAL_GID}} -
diff --git a/sysusers.d/systemd-network.conf.in b/sysusers.d/systemd-network.conf.in
index fc04827efd..5873bfab30 100644
--- a/sysusers.d/systemd-network.conf.in
Expand Down
25 changes: 25 additions & 0 deletions SPECS/systemd/harden-tmpfs-mount-options.patch
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
From c1f34abfcfc19124001babd51826aad864d95140 Mon Sep 17 00:00:00 2001
From: Shreenidhi Shedi <shreenidhi.shedi@broadcom.com>
Date: Fri, 26 Sep 2025 11:58:31 +0530
Subject: [PATCH] Harden tmpfs mount options

Ensure nosuid,noexec,nodev are enforced on tmpfs

Signed-off-by: Shreenidhi Shedi <shreenidhi.shedi@broadcom.com>
---
units/tmp.mount | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/units/tmp.mount b/units/tmp.mount
index 734acea..7b8fd9d 100644
--- a/units/tmp.mount
+++ b/units/tmp.mount
@@ -22,4 +22,4 @@ After=swap.target
What=tmpfs
Where=/tmp
Type=tmpfs
-Options=mode=1777,strictatime,nosuid,nodev,size=50%%,nr_inodes=1m
+Options=mode=1777,strictatime,nosuid,noexec,nodev,size=50%%,nr_inodes=1m
--
2.51.0

72 changes: 63 additions & 9 deletions SPECS/systemd/systemd.spec
Original file line number Diff line number Diff line change
@@ -1,13 +1,16 @@
%global build_if %{photon_subrelease} >= 91

%define STIG_HARDEN 0
# Default off, but overridable from pkg_build_options.json / rpmbuild -D.
# A plain define of STIG_HARDEN here would win over -D and make every
# conditional below permanently unreachable, and therefore untested.
%{!?STIG_HARDEN: %global STIG_HARDEN 0}

%global udev_services %{name}-udevd.service %{name}-udev-settle.service %{name}-udev-trigger.service %{name}-udevd-control.socket %{name}-udevd-kernel.socket %{name}-timesyncd.service

Name: systemd
URL: http://www.freedesktop.org/wiki/Software/systemd
Version: 257.13
Release: 5%{?dist}
Release: 7%{?dist}
Summary: System and Service Manager
Group: System Environment/Security
Vendor: VMware, Inc.
Expand Down Expand Up @@ -40,14 +43,25 @@ Source14: sysusers.generate-pre.sh
Source15: license.txt
%include %{SOURCE15}

Patch0: 0001-enoX-uses-instance-number-for-vmware-hv.patch
Patch1: 0002-Fetch-dns-servers-from-environment.patch
Patch2: 0003-systemd-do-not-use-ftrivial-auto-var-init-zero.patch
Patch3: 0004-Remove-unused-default-groups-rules-and-tmpfiles.patch
Patch4: 0005-default-conf-modifications.patch

# Unnumbered "Patch:" lets rpm assign indices in order, so a conditional
# patch can never collide with an unconditional one. Two independent edits
# both picking "Patch4:" is exactly how the STIG variant came to fail with
# "error: patch 4 defined multiple times".
Patch: 0001-enoX-uses-instance-number-for-vmware-hv.patch
Patch: 0002-Fetch-dns-servers-from-environment.patch
Patch: 0003-systemd-do-not-use-ftrivial-auto-var-init-zero.patch
Patch: 0004-Remove-unused-default-groups-rules-and-tmpfiles.patch
Patch: 0005-default-conf-modifications.patch

# /lib/systemd/system/tmp.mount is owned by this package and is not marked as
# a config file, so it must be hardened here, at build time. The installer
# deliberately skips
# the equivalent ansible control PHTN-50-000245 (stigenable.py) because editing
# a package-owned unit at install time shows up as permanent rpm -V drift and
# is reverted by the next systemd upgrade. Do not "fix" that skip; this is the
# owning side of that split.
%if 0%{?STIG_HARDEN}
Patch4: harden-tmpfs-mount-options.patch
Patch: harden-tmpfs-mount-options.patch
%endif

Conflicts: dracut < 109
Expand Down Expand Up @@ -274,6 +288,7 @@ CONFIGURE_OPTS=(
-Doomd=false
-Dhomed=disabled
-Dversion-tag=v%{version}-%{release}
-Dsystemd-journal-gid=23
-Dsystemd-network-uid=76
-Dsystemd-resolve-uid=77
-Dsystemd-timesync-uid=78
Expand Down Expand Up @@ -681,6 +696,45 @@ udevadm hwdb --update &>/dev/null || :
%files lang -f ../%{name}.lang

%changelog
* Mon Aug 31 2026 Daniel Casota <dcasota@gmail.com> 257.13-7
- Ship harden-tmpfs-mount-options.patch. It was referenced by the STIG
conditional but present only under SPECS/90/systemd, so a STIG build could
never have found it. Applies cleanly to 257.13.
- Replace the plain define of STIG_HARDEN with a define-if-unset, so the flag
can be set from pkg_build_options.json or rpmbuild -D. A plain define in the
spec body beats -D, which made every STIG conditional here unreachable and
therefore never parsed, built or tested.
- Switch the patch list to unnumbered "Patch:" so rpm assigns indices. The
conditional STIG patch and 0005-default-conf-modifications.patch had both
been given index 4; with STIG_HARDEN reachable that is a hard
"error: patch 4 defined multiple times" and no prep section is emitted.
Auto-numbering removes the collision class rather than this one instance.
- Constellation: the three defects above are invisible in every build Photon
currently performs (STIG_HARDEN pinned to 0) and all fire together the
moment the STIG variant is selected, on any arch and any subrelease >= 91.
Non-STIG builds are byte-identical before and after: same sources, same
five patches, same order.
* Mon Aug 31 2026 Daniel Casota <dcasota@gmail.com> 257.13-6
- 0004: also drop the SUBSYSTEM=="accel" rule from 50-udev-default.rules.in.
The same patch removes the "render" group from sysusers.d/basic.conf.in, but
the accel rule kept referencing it, so systemd-udevd logged
"50-udev-default.rules:56 Unknown group 'render', ignoring." on every boot.
systemd 253 had no accel rule; the regression arrived with the 253->257
rebase. The dev branch (255.10) already deletes this line.
- 0004: stop emptying sysusers.d/systemd-journal.conf.in. dracut 109 builds the
initrd's /etc/group by running systemd-sysusers against the shipped
sysusers.d snippets (11systemd-journald inst_sysusers systemd-journal.conf,
78systemd-sysusers systemd-sysusers --root=$initdir); with the entry removed
the snippet was a no-op, so the initrd had no systemd-journal group while
11systemd-tmpfiles still installed tmpfiles.d/systemd.conf, which references
it on 5 lines. Every boot logged 5x "Failed to resolve group
'systemd-journal'" from inside the initrd. Harmless under dracut 059, which
copied the group in explicitly; a real gap since the 109 bump.
- Pin -Dsystemd-journal-gid=23 to match filesystem's static group file. The
meson default is 0, which meson.build maps to "-" (dynamic allocation), so
restoring the sysusers entry without this would let systemd-sysusers pick an
arbitrary GID inside the initrd and mis-own /run/log/journal across
switch-root.
* Mon Jun 08 2026 Bo Gan <bo.gan@broadcom.com> 257.13-5
- Migrate from pcre to pcre2
* Wed Jun 03 2026 Harinadh Dommaraju <Harinadh.Dommaraju@broadcom.com> 257.13-4
Expand Down
Loading