resolved: Recover missing PrivateTmp=yes and ProtectSystem=strict
authorHATAYAMA Daisuke <d.hatayama@fujitsu.com>
Tue, 25 Feb 2020 18:35:50 +0000 (13:35 -0500)
committerThe Plumber <50238977+systemd-rhel-bot@users.noreply.github.com>
Wed, 1 Apr 2020 10:03:28 +0000 (12:03 +0200)
commitd9ae3222cfbd5d2a48e6dbade6617085cc76f1c1
tree3a4900e4e5761032ea21ed6a2072491d6ab68987
parentb89a1a9d19aa806feb984c8dba25116b5b5a52bc
resolved: Recover missing PrivateTmp=yes and ProtectSystem=strict

Since the commit b61e8046ebcb28225423fc0073183d68d4c577c4,
systemd-resolved.service often fails to start with the following message:

    Failed at step NAMESPACE spawning /usr/bin/mount: Read-only file system

This is because dropping DynamicUser=yes dropped implicit PrivateTmp=yes and
also implicit After=systemd-tmpfiles-setup.service, and thus
systemd-resolved.service can start before systemd-remount-fs.service. As a
result, mount operations associated with PrivateDevices= can be performed to
still read-only filesystems.

To fix this issue, it's better to recover PrivateTmp=yes and
ProtectSystem=strict just as the upstream commit
62fb7e80fcc45a1530ed58a84980be8cfafa9b3e (Revert "resolve: enable DynamicUser=
for systemd-resolved.service").

Resolves: #1810869
units/systemd-resolved.service.in