The Four Horsemen of The Naming Soup Apocalypse are now complete.
(Spoiler: the fourth one is real - see thread)
*Edit: forgot an important Fifth Horseman, mentioned in the comments:
This is all very efficient to secure services, but it's also a bit opaque: since it's the daemon you sandbox, and your admin tools are outside of that sandbox it's sometimes hard to analyze how the daemon sees things.
No more. With v258 there's a new verb "unit-shell" in systemd-analyze. You specify a service name, and it opens you a shell inside that specified services' sandbox (which must be running for this). You can look around and check if everything is like you expected it to be.
Literally every criticism of systemd I hear is just a variation on "I had to learn a new way of doing a thing that's different from how I've been doing it since the 70s, therefore Lennart is the Antichrist."
https://mastodonapp.uk/users/ljs/statuses/114822977834580322"Arbitrary File Read via file:// Protocol in cURL"
Well, you see... 🤦♂️
Day 2, again lots of great OSDI talks. My favorite was a systematic analysis of sequential performance optimization in practice.
https://www.usenix.org/conference/osdi25/presentation/park-sujin https://github.com/sslab-gatech/SysGPT