From gentoo-dev Wed May 08 20:06:02 2013 From: =?UTF-8?B?Q2jDrS1UaGFuaCBDaHJpc3RvcGhlciBOZ3V54buFbg==?= Date: Wed, 08 May 2013 20:06:02 +0000 To: gentoo-dev Subject: Re: [gentoo-dev] OpenRC supporting systemd units Message-Id: <518AB02A.7050602 () gentoo ! org> X-MARC-Message: https://marc.info/?l=gentoo-dev&m=136804357519865 Michael Mol schrieb: >> Sounds like a great feature. A crashed process is a buggy one, and I >> would want to investigate said program before I relaunched it, and >> not have it automatically relaunched as if nothing had happened. > > That's highly, highly, highly use-case dependent. If it's a > non-critical service, or in a non-critical environment, that's one > thing. If it's a service whose downtime can be measured in value lost, > that's quite another. You could be looking at someone trying to compromise your system through a buffer overflow or similar vulnerability. If you enable automatic respawn then congratulations, you just gave the attacker unlimited tries to guess the correct address/offset for his exploit. Best regards, Chí-Thanh Christopher Nguyễn