Re: Security of confined user/application and access to video group

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



2017-06-06 14:40 GMT+02:00 Lennart Poettering <mzerqung@xxxxxxxxxxx>:
> Note sure what "boinc-client" does, but if this isn't turstworthy then
> it probably shouldn't be able to get access to "video".

boinc-client is the client side version of BOINC (Berkeley Open
Infrastructure for Network Computing). You can use your computers to
help scientific research of many different projects. You can think
about it as a music player, the projects as the music discs, and the
working units as disc tracks.
Since working units are closed source software we always considered
them not trustworthy, therefore they always runned confined as much as
possible

>> ExecStopPost=/bin/rm -f /var/lib/boinc/lockfile
>
> If this file is not supposed to survive a daemon restart it really
> should be placed in /run somewhere.
>

I will take care of this.

>> Group=video
>
> I have the suspicion you should better
> use SupplementaryGroups=video than Group=, [...]

I will not use any of them, as soon as possible I will start
investigating on using udev/ACLs on dri/render to solve the GPU
detection problem.

Thank you for clarifing my dubts Lennart
Have a nice day!
_______________________________________________
devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx




[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux