<feed xmlns='http://www.w3.org/2005/Atom'>
<title>vyatta-cfg-system.git/sysconf, branch debian/0.17.76</title>
<subtitle>Vyatta system-level configuration templates/scripts (mirror of https://github.com/vyos/vyatta-cfg-system.git)
</subtitle>
<id>https://git.amelek.net/vyos/vyatta-cfg-system.git/atom?h=debian%2F0.17.76</id>
<link rel='self' href='https://git.amelek.net/vyos/vyatta-cfg-system.git/atom?h=debian%2F0.17.76'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyatta-cfg-system.git/'/>
<updated>2010-07-14T22:31:30+00:00</updated>
<entry>
<title>Enable putting core files /var/core</title>
<updated>2010-07-14T22:31:30+00:00</updated>
<author>
<name>Stephen Hemminger</name>
<email>stephen.hemminger@vyatta.com</email>
</author>
<published>2010-07-14T22:31:30+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyatta-cfg-system.git/commit/?id=dcab2aff7bf9659334e6dda7f50caccbe849213e'/>
<id>urn:sha1:dcab2aff7bf9659334e6dda7f50caccbe849213e</id>
<content type='text'>
For serviceablity put core files in /var/core.
But core file will still not be created unless process is running
with permission to write there, and has ulimit permission.
</content>
</entry>
<entry>
<title>Touch file before setting capability</title>
<updated>2010-07-01T20:36:26+00:00</updated>
<author>
<name>Stephen Hemminger</name>
<email>stephen.hemminger@vyatta.com</email>
</author>
<published>2010-07-01T19:00:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyatta-cfg-system.git/commit/?id=c2f18f972dacb630019cc229263efd2d8aef1428'/>
<id>urn:sha1:c2f18f972dacb630019cc229263efd2d8aef1428</id>
<content type='text'>
Unionfs should copyup the xattr automatically, but it doesn't
so use touch to force a copyup before setting attributes.
</content>
</entry>
<entry>
<title>Fix path to ipset</title>
<updated>2010-06-21T04:18:49+00:00</updated>
<author>
<name>Stephen Hemminger</name>
<email>stephen.hemminger@vyatta.com</email>
</author>
<published>2010-06-21T04:18:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyatta-cfg-system.git/commit/?id=7369bf61abd3eed1fdd17a56908cf2c0ffc9843f'/>
<id>urn:sha1:7369bf61abd3eed1fdd17a56908cf2c0ffc9843f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Don't need audit write on vbash</title>
<updated>2010-06-17T21:45:17+00:00</updated>
<author>
<name>Stephen Hemminger</name>
<email>stephen.hemminger@vyatta.com</email>
</author>
<published>2010-06-17T21:45:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyatta-cfg-system.git/commit/?id=f14c3c03a4c6cf4734272d370159dc904043ca2c'/>
<id>urn:sha1:f14c3c03a4c6cf4734272d370159dc904043ca2c</id>
<content type='text'>
Not using auditing for command logging.
</content>
</entry>
<entry>
<title>Remove capability from ping</title>
<updated>2010-06-16T17:43:45+00:00</updated>
<author>
<name>Stephen Hemminger</name>
<email>stephen.hemminger@vyatta.com</email>
</author>
<published>2010-06-16T17:43:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyatta-cfg-system.git/commit/?id=e7fa981b7038cca5df8c1e57a3d21f3745bd2697'/>
<id>urn:sha1:e7fa981b7038cca5df8c1e57a3d21f3745bd2697</id>
<content type='text'>
Ping is already setuid root.
</content>
</entry>
<entry>
<title>Add pam_cap capability configuration</title>
<updated>2010-06-04T21:09:56+00:00</updated>
<author>
<name>Stephen Hemminger</name>
<email>stephen.hemminger@vyatta.com</email>
</author>
<published>2010-05-25T17:21:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyatta-cfg-system.git/commit/?id=e902973f24c75b24576e914d44a68beaaf2aff5b'/>
<id>urn:sha1:e902973f24c75b24576e914d44a68beaaf2aff5b</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Set file capability attributes</title>
<updated>2010-06-04T21:09:51+00:00</updated>
<author>
<name>Stephen Hemminger</name>
<email>stephen.hemminger@vyatta.com</email>
</author>
<published>2010-05-25T15:56:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyatta-cfg-system.git/commit/?id=379c2618cfbc337625f809f63fd4cb22793eccf8'/>
<id>urn:sha1:379c2618cfbc337625f809f63fd4cb22793eccf8</id>
<content type='text'>
This sets file capability attributes during package
installation (and build) to allow better security models.
</content>
</entry>
<entry>
<title>Get rid of protected-users file</title>
<updated>2010-01-27T02:09:55+00:00</updated>
<author>
<name>Stephen Hemminger</name>
<email>stephen.hemminger@vyatta.com</email>
</author>
<published>2010-01-27T02:09:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyatta-cfg-system.git/commit/?id=471b7e4ada3ab3ce69da161b9546056332b60ce2'/>
<id>urn:sha1:471b7e4ada3ab3ce69da161b9546056332b60ce2</id>
<content type='text'>
Instead of white-listing special system users, just go with the
Debian policy that all users with uid &lt; 1000 are system accounts
</content>
</entry>
<entry>
<title>Set IPV6 parameters in rl-system.init</title>
<updated>2010-01-21T03:12:25+00:00</updated>
<author>
<name>Stephen Hemminger</name>
<email>stephen.hemminger@vyatta.com</email>
</author>
<published>2010-01-21T03:12:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyatta-cfg-system.git/commit/?id=8145d65a7b185b78d904d561fdb2420edb01369d'/>
<id>urn:sha1:8145d65a7b185b78d904d561fdb2420edb01369d</id>
<content type='text'>
The problem is that IPV6 module is not loaded when sysctl's
are interpreted during boot, and we want to allow marking IPV6
disabled.
</content>
</entry>
<entry>
<title>Change how IPV4/IPV6 configuration values are done</title>
<updated>2010-01-20T01:00:30+00:00</updated>
<author>
<name>Stephen Hemminger</name>
<email>stephen.hemminger@vyatta.com</email>
</author>
<published>2010-01-20T00:47:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyatta-cfg-system.git/commit/?id=6eb5483bb5bba3cb4efcc8d306724840c80ccb33'/>
<id>urn:sha1:6eb5483bb5bba3cb4efcc8d306724840c80ccb33</id>
<content type='text'>
1. Move vyatta-sysctl.conf from rl-system.init to procps
   This makes configuration happen early (before networking)

2. Do IPV6 configuration for address_flush in rl-system.init
   (after IPV6 is loaded)

3. Cleanup shell code for ipv6_params:
    * no sudo needed in startup scripts
    * use cleaner iteration
</content>
</entry>
</feed>
