Page MenuHomeFreeBSD

oomprotect sshd and local_unbound + documentation (incl. syslogd)
ClosedPublic

Authored by netchild on Nov 10 2023, 9:06 AM.
Tags
None
Referenced Files
Unknown Object (File)
Fri, Apr 26, 2:16 AM
Unknown Object (File)
Mon, Apr 22, 4:24 PM
Unknown Object (File)
Sun, Apr 14, 5:33 PM
Unknown Object (File)
Mon, Apr 8, 2:07 PM
Unknown Object (File)
Mar 13 2024, 2:45 AM
Unknown Object (File)
Feb 26 2024, 7:31 AM
Unknown Object (File)
Feb 9 2024, 10:09 AM
Unknown Object (File)
Jan 19 2024, 11:02 PM

Details

Summary

syslogd is already oomptotected (to not lose logs which may lead to the oom situation).
sshd also needs to be oomprotected for situations where there is no out-of-band console access.
The discussion in arch@ suggestedto add local_unbound too. Local services (including sshd) may rely on it when started.

This change adds sshd and local_unbound _oomprotext=YES to the defaults and documents it in (plus for syslogd) in rc.conf.5.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

netchild retitled this revision from oomprotext sshd and local_unbound + documentation (incl. syslogd) to oomprotect sshd and local_unbound + documentation (incl. syslogd).
This revision is now accepted and ready to land.Nov 10 2023, 9:09 AM

Typo

libexec/rc/rc.conf
321

s/oomprotext/oomprotect/

368

s/oomprotext/oomprotect/

This revision now requires review to proceed.Nov 10 2023, 11:09 AM
This revision is now accepted and ready to land.Nov 10 2023, 1:19 PM

Looks good to me. Thank you.

This revision was automatically updated to reflect the committed changes.