summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDenis Chevalier <perso@denischevalier.fr>2026-08-06 12:34:57 +0200
committerDenis Chevalier <perso@denischevalier.fr>2026-08-06 12:35:04 +0200
commit6343b37e9f3a473a81f6ecb0a0303bc9cd1b23ad (patch)
tree98e89692d00b9e9b27f693ddbb5d3a236ba01150
parenta35e6f911fa032bb61a0e327465f3dcdf357d8e6 (diff)
downloadpostinstall-6343b37e9f3a473a81f6ecb0a0303bc9cd1b23ad.tar.gz
postinstall-6343b37e9f3a473a81f6ecb0a0303bc9cd1b23ad.tar.bz2
postinstall-6343b37e9f3a473a81f6ecb0a0303bc9cd1b23ad.zip
prevent core dumps
-rwxr-xr-xetc.bash1
-rw-r--r--etc/sysctl.d/99-security.conf3
-rw-r--r--etc/systemd/coredump.conf30
3 files changed, 34 insertions, 0 deletions
diff --git a/etc.bash b/etc.bash
index da53128..6c46e23 100755
--- a/etc.bash
+++ b/etc.bash
@@ -7,6 +7,7 @@ sudo cp -v etc/pam.d/system-local-login /etc/pam.d/
sudo cp -v etc/pam.d/system-login /etc/pam.d/
sudo cp -v etc/login.defs /etc/
sudo cp -v etc/updatedb.conf /etc/
+sudo cp -v etc/systemd/coredump.conf /etc/systemd/
sudo cp -v etc/sysctl.d/99-security.conf /etc/sysctl.d/
sudo sysctl --system
diff --git a/etc/sysctl.d/99-security.conf b/etc/sysctl.d/99-security.conf
index a476e40..d2b9b1b 100644
--- a/etc/sysctl.d/99-security.conf
+++ b/etc/sysctl.d/99-security.conf
@@ -29,3 +29,6 @@ net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
+
+# Prevent setuid binaries or privileged processes from dumping core
+fs.suid_dumpable = 0
diff --git a/etc/systemd/coredump.conf b/etc/systemd/coredump.conf
new file mode 100644
index 0000000..7ec87e1
--- /dev/null
+++ b/etc/systemd/coredump.conf
@@ -0,0 +1,30 @@
+# This file is part of systemd.
+#
+# systemd is free software; you can redistribute it and/or modify it under the
+# terms of the GNU Lesser General Public License as published by the Free
+# Software Foundation; either version 2.1 of the License, or (at your option)
+# any later version.
+#
+# Entries in this file show the compile time defaults. Local configuration
+# should be created by either modifying this file (or a copy of it placed in
+# /etc/ if the original file is shipped in /usr/), or by creating "drop-ins" in
+# the /etc/systemd/coredump.conf.d/ directory. The latter is generally
+# recommended. Defaults can be restored by simply deleting the main
+# configuration file and all drop-ins located in /etc/.
+#
+# Use 'systemd-analyze cat-config systemd/coredump.conf' to display the full config.
+#
+# See coredump.conf(5) for details.
+
+[Coredump]
+Storage=none
+ProcessSizeMax=0
+#Storage=external
+#Compress=yes
+# On 32-bit, the default is 1G instead of 32G.
+#ProcessSizeMax=32G
+#ExternalSizeMax=32G
+#JournalSizeMax=767M
+#MaxUse=
+#KeepFree=
+#EnterNamespace=no