-
Notifications
You must be signed in to change notification settings - Fork 157
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
When /proc is mounted with hidepid=2, it doesn't work #161
Comments
Hi, what is hidepid? |
Add this in /etc/fstab, and processes will can see proc directories of only the same users. See https://linux-audit.com/linux-system-hardening-adding-hidepid-to-proc/ https://www.linux-dev.org/2012/09/hide-process-information-for-other-users/ |
How to test:
|
I think this is a similar situation as "/proc is not mounted". We can't do anything about it. |
No, it's not the same situation.
|
Is there a distribution that uses hidepid ? |
https://wiki.archlinux.org/index.php/Security#hidepid |
|
I set
|
-- this happens when supplementary group does not exist. |
Mount proc with |
It also works for me (SupplementaryGroups) This is a distribution level solution. Just mention it explicitly in README. |
Added to the wiki as https://github.com/rfjakob/earlyoom/wiki/proc-hidepid , thanks |
When /proc is mounted with hidepid=2, it doesn't work. The Earlyoom service can only see its own pid.
The text was updated successfully, but these errors were encountered: