diff options
| author | 2018-03-20 22:39:36 -0400 | |
|---|---|---|
| committer | 2018-03-20 22:56:18 -0400 | |
| commit | eb818b3324b9f53e285fa30d84246dd248af8f29 (patch) | |
| tree | eb2b27d7601e3b137fb7418f82d0a558ad764495 /debian/patches/policy.d_no_autostart.patch | |
| parent | d929c8cbc09732337fb4805accbf3564e9cca0bb (diff) | |
Import Debian changes 18-1
arch-install-scripts (18-1) UNRELEASED; urgency=medium
* Initial release.
Diffstat (limited to 'debian/patches/policy.d_no_autostart.patch')
| -rw-r--r-- | debian/patches/policy.d_no_autostart.patch | 42 |
1 files changed, 42 insertions, 0 deletions
diff --git a/debian/patches/policy.d_no_autostart.patch b/debian/patches/policy.d_no_autostart.patch new file mode 100644 index 0000000..5f2c799 --- /dev/null +++ b/debian/patches/policy.d_no_autostart.patch @@ -0,0 +1,42 @@ +Description: Setup and teardown policy.d, to not autostart applications in the chroot +Author: Unit 193 <unit193@ubuntu.com> +Origin: vendor +Forwarded: not-needed +Last-Update: 2018-01-28 + +--- arch-install-scripts-15.orig/common ++++ arch-install-scripts-15/common +@@ -74,10 +74,18 @@ chroot_maybe_add_mount() { + fi + } + ++chroot_policyd() { ++ cat << EOF > "$1/usr/sbin/policy-rc.d" ++#!/bin/sh ++exit 101 ++EOF ++ chmod +x "$1/usr/sbin/policy-rc.d" ++} ++ + chroot_setup() { + CHROOT_ACTIVE_MOUNTS=() + [[ $(trap -p EXIT) ]] && die '(BUG): attempting to overwrite existing EXIT trap' +- trap 'chroot_teardown' EXIT ++ trap "chroot_teardown $1" EXIT + + chroot_add_mount proc "$1/proc" -t proc -o nosuid,noexec,nodev && + chroot_add_mount sys "$1/sys" -t sysfs -o nosuid,noexec,nodev,ro && +@@ -88,11 +96,13 @@ chroot_setup() { + chroot_add_mount shm "$1/dev/shm" -t tmpfs -o mode=1777,nosuid,nodev && + chroot_add_mount run "$1/run" -t tmpfs -o nosuid,nodev,mode=0755 && + chroot_add_mount tmp "$1/tmp" -t tmpfs -o mode=1777,strictatime,nodev,nosuid ++ chroot_policyd "$1" + } + + chroot_teardown() { + umount "${CHROOT_ACTIVE_MOUNTS[@]}" + unset CHROOT_ACTIVE_MOUNTS ++ rm -f "$1/usr/sbin/policy-rc.d" + } + + try_cast() ( |
