[Bug 1226464] New: AUDIT-0: aaa_base: sysctl.d/50-default.conf has new defaults
https://bugzilla.suse.com/show_bug.cgi?id=1226464 Bug ID: 1226464 Summary: AUDIT-0: aaa_base: sysctl.d/50-default.conf has new defaults Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: kukuk@suse.com QA Contact: qa-bugs@suse.de Target Milestone: --- Found By: --- Blocker: --- sysctl.d/50-default.conf in aaa_base has new defaults: Remove kernel.pid_max limit (bsc#1219038) kernel.pid_max is one of multiple mechanisms to restrict number of processes [1]. Its kernel default is scaled with nr_cpus but 1024 tasks/cpu cap is too much if they were all running and it is also too little when they are idle (memory being bottleneck). Bump the limit to maximum kernel-accepted value and defer to other mechanisms for tasks limit enforcing. (This way we converge to same config like upstream systemd [2] but we ship distro defaults together from this package.) [1] https://www.suse.com/support/kb/doc/?id=000020429 [2] https://github.com/systemd/systemd/blob/72192b6cc9b856c10abc7f1e5f98240fde17... -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1226464 Thorsten Kukuk <kukuk@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |ro@suse.com -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1226464 https://bugzilla.suse.com/show_bug.cgi?id=1226464#c1 --- Comment #1 from Matthias Gerstner <matthias.gerstner@suse.com> --- Thank you for creating the AUDIT bug. We will schedule the review and whitelisting. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1226464 https://bugzilla.suse.com/show_bug.cgi?id=1226464#c2 Matthias Gerstner <matthias.gerstner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|security-team@suse.de |matthias.gerstner@suse.com CC| |security-team@suse.de Status|NEW |IN_PROGRESS --- Comment #2 from Matthias Gerstner <matthias.gerstner@suse.com> --- I will handle this -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1226464 https://bugzilla.suse.com/show_bug.cgi?id=1226464#c3 Matthias Gerstner <matthias.gerstner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Summary|AUDIT-0: aaa_base: |AUDIT-WHITELIST: aaa_base: |sysctl.d/50-default.conf |sysctl.d/50-default.conf |has new defaults |has new defaults --- Comment #3 from Matthias Gerstner <matthias.gerstner@suse.com> --- Change should be fine, we can start the whitelisting adaption process. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1226464 https://bugzilla.suse.com/show_bug.cgi?id=1226464#c5 Matthias Gerstner <matthias.gerstner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|IN_PROGRESS |RESOLVED Resolution|--- |FIXED --- Comment #5 from Matthias Gerstner <matthias.gerstner@suse.com> --- the whitelisting is now in Factory, closing as fixed -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com