mirror of
				https://github.com/TommyTran732/Fedora-CoreOS-Ignition.git
				synced 2025-11-04 11:08:35 +01:00 
			
		
		
		
	ld.preload path does not needed to be hardcoded
Signed-off-by: Tommy <contact@tommytran.io>
This commit is contained in:
		@@ -236,7 +236,7 @@
 | 
			
		||||
        "name": "postinst.service"
 | 
			
		||||
      },
 | 
			
		||||
      {
 | 
			
		||||
        "contents": "[Unit]\nDescription=Initial System Setup Part 2\n# We run this after the packages have been overlayed\nAfter=network-online.target\nConditionPathExists=!/var/lib/%N.stamp\nConditionPathExists=/var/lib/postinst.stamp\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=/usr/bin/echo \"/lib64/glibc-hwcaps/x86-64-v3/libhardened_malloc.so\" | tee /etc/ld.so.preload\nExecStart=/usr/bin/systemctl enable --now firewalld\nExecStart=/usr/bin/firewall-cmd --lockdown-on\nExecStart=/usr/bin/systemctl --no-block reboot\n\n[Install]\nWantedBy=multi-user.target\n",
 | 
			
		||||
        "contents": "[Unit]\nDescription=Initial System Setup Part 2\n# We run this after the packages have been overlayed\nAfter=network-online.target\nConditionPathExists=!/var/lib/%N.stamp\nConditionPathExists=/var/lib/postinst.stamp\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=/usr/bin/echo \"libhardened_malloc.so\" | tee /etc/ld.so.preload\nExecStart=/usr/bin/systemctl enable --now firewalld\nExecStart=/usr/bin/firewall-cmd --lockdown-on\nExecStart=/usr/bin/systemctl --no-block reboot\n\n[Install]\nWantedBy=multi-user.target\n",
 | 
			
		||||
        "enabled": true,
 | 
			
		||||
        "name": "postinst2.service"
 | 
			
		||||
      },
 | 
			
		||||
@@ -69,7 +69,7 @@ systemd:
 | 
			
		||||
        [Service]
 | 
			
		||||
        Type=oneshot
 | 
			
		||||
        RemainAfterExit=yes
 | 
			
		||||
        ExecStart=/usr/bin/echo "/lib64/glibc-hwcaps/x86-64-v3/libhardened_malloc.so" | tee /etc/ld.so.preload
 | 
			
		||||
        ExecStart=/usr/bin/echo "libhardened_malloc.so" | tee /etc/ld.so.preload
 | 
			
		||||
        ExecStart=/usr/bin/systemctl enable --now firewalld
 | 
			
		||||
        ExecStart=/usr/bin/firewall-cmd --lockdown-on
 | 
			
		||||
        ExecStart=/usr/bin/systemctl --no-block reboot
 | 
			
		||||
		Reference in New Issue
	
	Block a user