Jan 19 2023
Due to phabricator being deprecated upstream, all tickets need to me migrated. Therefore closing here.
Dec 8 2022
This is for whonix.org server security?
Jan 12 2021
I am not sure sdwdate-gui would be a strong enough notification if networking was actually blocked if sdwdate did not succeed yet.
Feb 16 2020
Dec 8 2019
Nov 6 2019
This was done. If not, please create specific tickets where it isn't done.
Sep 14 2019
Jul 8 2019
Removed a few. Would not start without openat, so kept.
Yay, we have ProtectSystem=strict now.
Jul 7 2019
Yay, we have ProtectSystem=strict now.
Can we exclude ExecStartPre=/usr/lib/onion-grater-merger from systemd hardening?
Error back after reboot.
Jul 6 2019
https://github.com/Whonix/onion-grater/blob/master/lib/systemd/system/onion-grater.service currently works without ReadWritePaths. So let's not add?
https://github.com/Whonix/onion-grater/blob/master/lib/systemd/system/onion-grater.service currently works without ReadWritePaths. So let's not add?
Jul 4 2019
It's a file, not a folder.
It's a file, not a folder. Nothing in the code of
/usr/lib/onion-grater-merger writes to /usr/lib/onion-grater-merger.
Jul 3 2019
I just re-read the error message. Try adding
That's weird. Onion-grater is trying to write to somewhere that's being mounted read-only by systemd.
Jul 1 2019
Merged your changes.
Jun 29 2019
needrestart works good enough for it to be implemented as a test in whonixcheck (--verbose?).
Jun 24 2019
Jun 23 2019
Does it work after you comment ProtectSystem=strict and ReadWriteDirectories=? I think on Qubes-Whonix it is trying to write to a directory in /var/run (probably /var/run/qubes-service). I can't test as I don't use Qubes.
Unfortunately not. On Qubes-Whonix. Could be Non-Qubes-Whonix vs
Qubes-Whonix?
Does it work using this? It looks like it needs the openat syscall which it now allows.
Does not work yet. @madaidan