Re: Securing bind with systemd methods (was: bind-mount of /run/systemd for chrooted bind9/named)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, Jul 18, 2023 at 01:10:16AM +0300, Mantas Mikulėnas wrote:
> On Mon, Jul 17, 2023, 15:44 Marc Haber <mh+systemd-devel@xxxxxxxxxxxx>
> wrote:
> > # /lib is necessary here, or execve will fail without indication for
> > # reason - that was a surprise and hard to debug because even strace
> > # didnt hint me towards the real issue
> > ExecPaths=/usr/sbin/named /usr/sbin/rndc /lib
> >
> 
> This one in particular is not a systemd issue:

I never claimed it to be.

> All dynamically linked
> binaries are executed through /lib/ld-linux*.so as their "interpreter".
> (`file` will show the exact path.) I wish that had a dedicated errno,
> though.

That would be /usr/lib/x86_64-linux-gnu/ld-linux-x86-64.so.2 on my
system (only output of find /lib /usr/lib -name 'ld-lin*'), and adding
that to ExecPaths doesnt allow my Executable to run. So it must be
something else (possibly in addition).

Greetings
Marc


-- 
-----------------------------------------------------------------------------
Marc Haber         | "I don't trust Computers. They | Mailadresse im Header
Leimen, Germany    |  lose things."    Winona Ryder | Fon: *49 6224 1600402
Nordisch by Nature |  How to make an American Quilt | Fax: *49 6224 1600421



[Index of Archives]     [LARTC]     [Bugtraq]     [Yosemite Forum]     [Photo]

  Powered by Linux