Skip to content

Commit 8d02857

Browse files
authored
Merge pull request #216 from arnaldo2792/cherry-pick-3.1.x
Revert "add default security settings"
2 parents ae54c77 + c706bd2 commit 8d02857

File tree

4 files changed

+8
-8
lines changed

4 files changed

+8
-8
lines changed

CHANGELOG.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,10 @@
1+
# v3.1.1 (2024-10-24)
2+
3+
## OS Changes
4+
* Revert system-wide configuration to block writeable/executable memory in systemd services ([#215])
5+
6+
[#215]: https://github.com/bottlerocket-os/bottlerocket-core-kit/pull/215
7+
18
# v3.1.0 (2024-10-22)
29

310
## OS Changes

Twoliter.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
schema-version = 1
2-
release-version = "3.1.0"
2+
release-version = "3.1.1"
33

44
[vendor.bottlerocket]
55
registry = "public.ecr.aws/bottlerocket"

packages/release/release.spec

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,6 @@ Source1100: systemd-tmpfiles-setup-service-debug.conf
8787
Source1101: systemd-resolved-service-env.conf
8888
Source1102: systemd-networkd-service-env.conf
8989
Source1103: systemd-logind-inhibit-maxdelay.conf
90-
Source1104: systemd-service-security.conf
9190

9291
# network link rules
9392
Source1200: 80-release.link
@@ -208,9 +207,6 @@ install -d %{buildroot}%{_cross_unitdir}/systemd-networkd.service.d
208207
install -p -m 0644 %{S:1102} \
209208
%{buildroot}%{_cross_unitdir}/systemd-networkd.service.d/00-env.conf
210209

211-
install -d %{buildroot}%{_cross_unitdir}/service.d/
212-
install -p -m 0644 %{S:1104} %{buildroot}%{_cross_unitdir}/service.d/10-security.conf
213-
214210
# Empty (but packaged) directory. The FIPS packages for kernels will add drop-ins to
215211
# this directory to arrange for the right modules to be loaded before the check runs.
216212
install -d %{buildroot}%{_cross_unitdir}/check-fips-modules.service.d
@@ -316,7 +312,6 @@ ln -s preconfigured.target %{buildroot}%{_cross_unitdir}/default.target
316312
%{_cross_unitdir}/prepare-local-fs.service
317313
%{_cross_unitdir}/[email protected]
318314
%{_cross_unitdir}/[email protected]
319-
%{_cross_unitdir}/service.d/10-security.conf
320315
%dir %{_cross_unitdir}/systemd-resolved.service.d
321316
%{_cross_unitdir}/systemd-resolved.service.d/00-env.conf
322317
%dir %{_cross_unitdir}/systemd-networkd.service.d

packages/release/systemd-service-security.conf

Lines changed: 0 additions & 2 deletions
This file was deleted.

0 commit comments

Comments
 (0)