Add safe hardening to mariadb.service units
authorAquila Macedo <aquilamacedo@riseup.net>
Fri, 16 Jan 2026 00:53:16 +0000 (19:53 -0500)
committerOtto Kekäläinen <otto@debian.org>
Thu, 19 Mar 2026 13:13:13 +0000 (13:13 +0000)
commitc007835898a737ba8b5cc47d8813359001dfae0b
tree82996db471df5dbb6c99ae903bffb59a84dafcca
parentafea6182ee606cfa11065e89d87958da29246da9
Add safe hardening to mariadb.service units

Add low regression systemd hardening directives to mariadb.service and
mariadb@.service to improve 'systemd-analyze security' without touching
the historically-problematic areas (capability bounding /
NoNewPrivileges / PrivateDevices). Refs: MDEV-10404, MDEV-19878,
MDEV-36591, MDEV-36681

Includes kernel/cgroup protections, disables realtime scheduling, locks
personality, and restricts namespace creation (overrideable via drop-in)

This patch should be submitted upstream once proven stable in Debian.

Forwarded: no

Gbp-Pq: Name systemd-hardening-safe-defaults.patch
support-files/mariadb.service.in
support-files/mariadb@.service.in