From 36cc56e35da66dc64d45cb5eb17fbf7b1b1faec9 Mon Sep 17 00:00:00 2001 From: Daniel Casota Date: Mon, 31 Aug 2026 11:44:51 +0200 Subject: [PATCH] systemd 257.13-6: fix two group regressions and repair the STIG build variant Five defects, each invisible in some constellations and fatal in others. Group regressions (affect EVERY constellation) 0004: also drop the SUBSYSTEM=="accel" rule from 50-udev-default.rules.in. The same patch removes the "render" group from sysusers.d/basic.conf.in but left the accel rule referencing it, so systemd-udevd logs "50-udev-default.rules:56 Unknown group 'render', ignoring." on every boot of every install. systemd 253 had no accel rule; the regression arrived with the 253->257 rebase. The dev branch (255.10) already deletes this line. 0004: stop emptying sysusers.d/systemd-journal.conf.in. dracut 109 builds the initrd's /etc/group by running systemd-sysusers against the shipped snippets; with the entry removed the snippet is a no-op, so the initrd has no systemd-journal group while 11systemd-tmpfiles still installs tmpfiles.d/systemd.conf, which references it on five lines. Every boot logs five "Failed to resolve group 'systemd-journal'" from inside the initrd. Harmless under dracut 059, which copied the group in explicitly; a real gap since the 109 bump on 5.0. Pin -Dsystemd-journal-gid=23 to match filesystem's static group file. The meson default is 0, which meson.build maps to "-" (dynamic allocation), so restoring the sysusers entry without this would let systemd-sysusers pick an arbitrary GID in the initrd and mis-own /run/log/journal across switch-root. STIG build variant (affects only STIG_HARDEN=1) Ship harden-tmpfs-mount-options.patch. It was referenced by the STIG conditional but existed only under SPECS/90/systemd; it was dropped from this directory in 17c93651f "systemd: upgrade to v257.13". Replace the plain define of STIG_HARDEN with a define-if-unset so the flag can be set from pkg_build_options.json or rpmbuild -D. A plain define in the spec body beats -D, which made every STIG conditional unreachable and thus never parsed, built or tested. Switch to unnumbered "Patch:" so rpm assigns indices. The conditional STIG patch and 0005-default-conf-modifications.patch had both been given index 4; once STIG_HARDEN is reachable that is a hard "error: patch 4 defined multiple times" with no prep section emitted. Non-STIG builds are unchanged: the expanded %prep is byte-identical before and after at subrelease 91 and 92. Change-Id: I430c22804c50d5a9cae83043139f4de787ef2864 Signed-off-by: Daniel Casota Co-Authored-By: Claude Opus 5.5 --- ...ed-default-groups-rules-and-tmpfiles.patch | 19 +++------- .../systemd/harden-tmpfs-mount-options.patch | 25 +++++++++++++ SPECS/systemd/systemd.spec | 35 ++++++++++++++----- 3 files changed, 55 insertions(+), 24 deletions(-) create mode 100644 SPECS/systemd/harden-tmpfs-mount-options.patch diff --git a/SPECS/systemd/0004-Remove-unused-default-groups-rules-and-tmpfiles.patch b/SPECS/systemd/0004-Remove-unused-default-groups-rules-and-tmpfiles.patch index 2912b778d9..7ad2e4063c 100644 --- a/SPECS/systemd/0004-Remove-unused-default-groups-rules-and-tmpfiles.patch +++ b/SPECS/systemd/0004-Remove-unused-default-groups-rules-and-tmpfiles.patch @@ -5,27 +5,26 @@ Subject: [PATCH 4/4] Remove unused default groups, rules and tmpfiles Some of these groups and users are also created by filesystem --- - rules.d/50-udev-default.rules.in | 11 --------- + rules.d/50-udev-default.rules.in | 12 ---------- sysusers.d/basic.conf.in | 26 --------------------- - sysusers.d/systemd-journal.conf.in | 2 -- sysusers.d/systemd-network.conf.in | 2 -- sysusers.d/systemd-remote.conf | 2 -- sysusers.d/systemd-resolve.conf.in | 2 -- sysusers.d/systemd-timesync.conf.in | 2 -- tmpfiles.d/static-nodes-permissions.conf.in | 3 --- - 8 files changed, 50 deletions(-) + 7 files changed, 49 deletions(-) diff --git a/rules.d/50-udev-default.rules.in b/rules.d/50-udev-default.rules.in index 8fa518cd8f..23f43d0409 100644 --- a/rules.d/50-udev-default.rules.in +++ b/rules.d/50-udev-default.rules.in -@@ -53,13 +53,8 @@ SUBSYSTEM=="dvb", GROUP="video" +@@ -53,13 +53,7 @@ SUBSYSTEM=="dvb", GROUP="video" SUBSYSTEM=="media", GROUP="video" SUBSYSTEM=="cec", GROUP="video" -SUBSYSTEM=="drm", KERNEL=="renderD*", GROUP="render", MODE="{{GROUP_RENDER_MODE}}" -SUBSYSTEM=="kfd", GROUP="render", MODE="{{GROUP_RENDER_MODE}}" - SUBSYSTEM=="accel", GROUP="render", MODE="{{GROUP_RENDER_MODE}}" +-SUBSYSTEM=="accel", GROUP="render", MODE="{{GROUP_RENDER_MODE}}" -SUBSYSTEM=="misc", KERNEL=="sgx_enclave", GROUP="sgx", MODE="0660" -SUBSYSTEM=="misc", KERNEL=="sgx_vepc", GROUP="sgx", MODE="0660" @@ -91,16 +90,6 @@ index 992af346ca..c66181be00 100644 - -# Default group for normal users -g users {{USERS_GID }} - - -diff --git a/sysusers.d/systemd-journal.conf.in b/sysusers.d/systemd-journal.conf.in -index 61768b234e..5873bfab30 100644 ---- a/sysusers.d/systemd-journal.conf.in -+++ b/sysusers.d/systemd-journal.conf.in -@@ -4,5 +4,3 @@ - # under the terms of the GNU Lesser General Public License as published by - # the Free Software Foundation; either version 2.1 of the License, or - # (at your option) any later version. -- --g systemd-journal {{SYSTEMD_JOURNAL_GID}} - diff --git a/sysusers.d/systemd-network.conf.in b/sysusers.d/systemd-network.conf.in index fc04827efd..5873bfab30 100644 --- a/sysusers.d/systemd-network.conf.in diff --git a/SPECS/systemd/harden-tmpfs-mount-options.patch b/SPECS/systemd/harden-tmpfs-mount-options.patch new file mode 100644 index 0000000000..9be3fe759e --- /dev/null +++ b/SPECS/systemd/harden-tmpfs-mount-options.patch @@ -0,0 +1,25 @@ +From c1f34abfcfc19124001babd51826aad864d95140 Mon Sep 17 00:00:00 2001 +From: Shreenidhi Shedi +Date: Fri, 26 Sep 2025 11:58:31 +0530 +Subject: [PATCH] Harden tmpfs mount options + +Ensure nosuid,noexec,nodev are enforced on tmpfs + +Signed-off-by: Shreenidhi Shedi +--- + units/tmp.mount | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/units/tmp.mount b/units/tmp.mount +index 734acea..7b8fd9d 100644 +--- a/units/tmp.mount ++++ b/units/tmp.mount +@@ -22,4 +22,4 @@ After=swap.target + What=tmpfs + Where=/tmp + Type=tmpfs +-Options=mode=1777,strictatime,nosuid,nodev,size=50%%,nr_inodes=1m ++Options=mode=1777,strictatime,nosuid,noexec,nodev,size=50%%,nr_inodes=1m +-- +2.51.0 + diff --git a/SPECS/systemd/systemd.spec b/SPECS/systemd/systemd.spec index be48620684..72860a9c1d 100644 --- a/SPECS/systemd/systemd.spec +++ b/SPECS/systemd/systemd.spec @@ -1,13 +1,16 @@ %global build_if %{photon_subrelease} >= 91 -%define STIG_HARDEN 0 +# Default off, but overridable from pkg_build_options.json / rpmbuild -D. +# A plain define of STIG_HARDEN here would win over -D and make every +# conditional below permanently unreachable, and therefore untested. +%{!?STIG_HARDEN: %global STIG_HARDEN 0} %global udev_services %{name}-udevd.service %{name}-udev-settle.service %{name}-udev-trigger.service %{name}-udevd-control.socket %{name}-udevd-kernel.socket %{name}-timesyncd.service Name: systemd URL: http://www.freedesktop.org/wiki/Software/systemd Version: 257.13 -Release: 5%{?dist} +Release: 6%{?dist} Summary: System and Service Manager Group: System Environment/Security Vendor: VMware, Inc. @@ -40,14 +43,25 @@ Source14: sysusers.generate-pre.sh Source15: license.txt %include %{SOURCE15} -Patch0: 0001-enoX-uses-instance-number-for-vmware-hv.patch -Patch1: 0002-Fetch-dns-servers-from-environment.patch -Patch2: 0003-systemd-do-not-use-ftrivial-auto-var-init-zero.patch -Patch3: 0004-Remove-unused-default-groups-rules-and-tmpfiles.patch -Patch4: 0005-default-conf-modifications.patch - +# Unnumbered "Patch:" lets rpm assign indices in order, so a conditional +# patch can never collide with an unconditional one. Two independent edits +# both picking "Patch4:" is exactly how the STIG variant came to fail with +# "error: patch 4 defined multiple times". +Patch: 0001-enoX-uses-instance-number-for-vmware-hv.patch +Patch: 0002-Fetch-dns-servers-from-environment.patch +Patch: 0003-systemd-do-not-use-ftrivial-auto-var-init-zero.patch +Patch: 0004-Remove-unused-default-groups-rules-and-tmpfiles.patch +Patch: 0005-default-conf-modifications.patch + +# /lib/systemd/system/tmp.mount is owned by this package and is not marked as +# a config file, so it must be hardened here, at build time. The installer +# deliberately skips +# the equivalent ansible control PHTN-50-000245 (stigenable.py) because editing +# a package-owned unit at install time shows up as permanent rpm -V drift and +# is reverted by the next systemd upgrade. Do not "fix" that skip; this is the +# owning side of that split. %if 0%{?STIG_HARDEN} -Patch4: harden-tmpfs-mount-options.patch +Patch: harden-tmpfs-mount-options.patch %endif Conflicts: dracut < 109 @@ -274,6 +288,7 @@ CONFIGURE_OPTS=( -Doomd=false -Dhomed=disabled -Dversion-tag=v%{version}-%{release} + -Dsystemd-journal-gid=23 -Dsystemd-network-uid=76 -Dsystemd-resolve-uid=77 -Dsystemd-timesync-uid=78 @@ -681,6 +696,8 @@ udevadm hwdb --update &>/dev/null || : %files lang -f ../%{name}.lang %changelog +* Mon Aug 31 2026 Daniel Casota 257.13-6 +- Fix render/systemd-journal groups; repair the STIG build variant * Mon Jun 08 2026 Bo Gan 257.13-5 - Migrate from pcre to pcre2 * Wed Jun 03 2026 Harinadh Dommaraju 257.13-4