Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -5,27 +5,26 @@ Subject: [PATCH 4/4] Remove unused default groups, rules and tmpfiles

Some of these groups and users are also created by filesystem
---
rules.d/50-udev-default.rules.in | 11 ---------
rules.d/50-udev-default.rules.in | 12 ----------
sysusers.d/basic.conf.in | 26 ---------------------
sysusers.d/systemd-journal.conf.in | 2 --
sysusers.d/systemd-network.conf.in | 2 --
sysusers.d/systemd-remote.conf | 2 --
sysusers.d/systemd-resolve.conf.in | 2 --
sysusers.d/systemd-timesync.conf.in | 2 --
tmpfiles.d/static-nodes-permissions.conf.in | 3 ---
8 files changed, 50 deletions(-)
7 files changed, 49 deletions(-)

diff --git a/rules.d/50-udev-default.rules.in b/rules.d/50-udev-default.rules.in
index 8fa518cd8f..23f43d0409 100644
--- a/rules.d/50-udev-default.rules.in
+++ b/rules.d/50-udev-default.rules.in
@@ -53,13 +53,8 @@ SUBSYSTEM=="dvb", GROUP="video"
@@ -53,13 +53,7 @@ SUBSYSTEM=="dvb", GROUP="video"
SUBSYSTEM=="media", GROUP="video"
SUBSYSTEM=="cec", GROUP="video"

-SUBSYSTEM=="drm", KERNEL=="renderD*", GROUP="render", MODE="{{GROUP_RENDER_MODE}}"
-SUBSYSTEM=="kfd", GROUP="render", MODE="{{GROUP_RENDER_MODE}}"
SUBSYSTEM=="accel", GROUP="render", MODE="{{GROUP_RENDER_MODE}}"
-SUBSYSTEM=="accel", GROUP="render", MODE="{{GROUP_RENDER_MODE}}"

-SUBSYSTEM=="misc", KERNEL=="sgx_enclave", GROUP="sgx", MODE="0660"
-SUBSYSTEM=="misc", KERNEL=="sgx_vepc", GROUP="sgx", MODE="0660"
Expand Down Expand Up @@ -91,16 +90,6 @@ index 992af346ca..c66181be00 100644
-
-# Default group for normal users
-g users {{USERS_GID }} - -
diff --git a/sysusers.d/systemd-journal.conf.in b/sysusers.d/systemd-journal.conf.in
index 61768b234e..5873bfab30 100644
--- a/sysusers.d/systemd-journal.conf.in
+++ b/sysusers.d/systemd-journal.conf.in
@@ -4,5 +4,3 @@
# under the terms of the GNU Lesser General Public License as published by
# the Free Software Foundation; either version 2.1 of the License, or
# (at your option) any later version.
-
-g systemd-journal {{SYSTEMD_JOURNAL_GID}} -
diff --git a/sysusers.d/systemd-network.conf.in b/sysusers.d/systemd-network.conf.in
index fc04827efd..5873bfab30 100644
--- a/sysusers.d/systemd-network.conf.in
Expand Down
25 changes: 25 additions & 0 deletions SPECS/systemd/harden-tmpfs-mount-options.patch
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
From c1f34abfcfc19124001babd51826aad864d95140 Mon Sep 17 00:00:00 2001
From: Shreenidhi Shedi <shreenidhi.shedi@broadcom.com>
Date: Fri, 26 Sep 2025 11:58:31 +0530
Subject: [PATCH] Harden tmpfs mount options

Ensure nosuid,noexec,nodev are enforced on tmpfs

Signed-off-by: Shreenidhi Shedi <shreenidhi.shedi@broadcom.com>
---
units/tmp.mount | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/units/tmp.mount b/units/tmp.mount
index 734acea..7b8fd9d 100644
--- a/units/tmp.mount
+++ b/units/tmp.mount
@@ -22,4 +22,4 @@ After=swap.target
What=tmpfs
Where=/tmp
Type=tmpfs
-Options=mode=1777,strictatime,nosuid,nodev,size=50%%,nr_inodes=1m
+Options=mode=1777,strictatime,nosuid,noexec,nodev,size=50%%,nr_inodes=1m
--
2.51.0

35 changes: 26 additions & 9 deletions SPECS/systemd/systemd.spec
Original file line number Diff line number Diff line change
@@ -1,13 +1,16 @@
%global build_if %{photon_subrelease} >= 91

%define STIG_HARDEN 0
# Default off, but overridable from pkg_build_options.json / rpmbuild -D.
# A plain define of STIG_HARDEN here would win over -D and make every
# conditional below permanently unreachable, and therefore untested.
%{!?STIG_HARDEN: %global STIG_HARDEN 0}

%global udev_services %{name}-udevd.service %{name}-udev-settle.service %{name}-udev-trigger.service %{name}-udevd-control.socket %{name}-udevd-kernel.socket %{name}-timesyncd.service

Name: systemd
URL: http://www.freedesktop.org/wiki/Software/systemd
Version: 257.13
Release: 5%{?dist}
Release: 6%{?dist}
Summary: System and Service Manager
Group: System Environment/Security
Vendor: VMware, Inc.
Expand Down Expand Up @@ -40,14 +43,25 @@ Source14: sysusers.generate-pre.sh
Source15: license.txt
%include %{SOURCE15}

Patch0: 0001-enoX-uses-instance-number-for-vmware-hv.patch
Patch1: 0002-Fetch-dns-servers-from-environment.patch
Patch2: 0003-systemd-do-not-use-ftrivial-auto-var-init-zero.patch
Patch3: 0004-Remove-unused-default-groups-rules-and-tmpfiles.patch
Patch4: 0005-default-conf-modifications.patch

# Unnumbered "Patch:" lets rpm assign indices in order, so a conditional
# patch can never collide with an unconditional one. Two independent edits
# both picking "Patch4:" is exactly how the STIG variant came to fail with
# "error: patch 4 defined multiple times".
Patch: 0001-enoX-uses-instance-number-for-vmware-hv.patch
Patch: 0002-Fetch-dns-servers-from-environment.patch
Patch: 0003-systemd-do-not-use-ftrivial-auto-var-init-zero.patch
Patch: 0004-Remove-unused-default-groups-rules-and-tmpfiles.patch
Patch: 0005-default-conf-modifications.patch

# /lib/systemd/system/tmp.mount is owned by this package and is not marked as
# a config file, so it must be hardened here, at build time. The installer
# deliberately skips
# the equivalent ansible control PHTN-50-000245 (stigenable.py) because editing
# a package-owned unit at install time shows up as permanent rpm -V drift and
# is reverted by the next systemd upgrade. Do not "fix" that skip; this is the
# owning side of that split.
%if 0%{?STIG_HARDEN}
Patch4: harden-tmpfs-mount-options.patch
Patch: harden-tmpfs-mount-options.patch
%endif

Conflicts: dracut < 109
Expand Down Expand Up @@ -274,6 +288,7 @@ CONFIGURE_OPTS=(
-Doomd=false
-Dhomed=disabled
-Dversion-tag=v%{version}-%{release}
-Dsystemd-journal-gid=23
-Dsystemd-network-uid=76
-Dsystemd-resolve-uid=77
-Dsystemd-timesync-uid=78
Expand Down Expand Up @@ -681,6 +696,8 @@ udevadm hwdb --update &>/dev/null || :
%files lang -f ../%{name}.lang

%changelog
* Mon Aug 31 2026 Daniel Casota <dcasota@gmail.com> 257.13-6
- Fix render/systemd-journal groups; repair the STIG build variant
* Mon Jun 08 2026 Bo Gan <bo.gan@broadcom.com> 257.13-5
- Migrate from pcre to pcre2
* Wed Jun 03 2026 Harinadh Dommaraju <Harinadh.Dommaraju@broadcom.com> 257.13-4
Expand Down
Loading