On Mon, Oct 02, 2017 at 11:07:48AM -0700, Laura Abbott wrote: > Thinking about this a bit more, I'm not 100% sure if this > will allow the security rules we want. Heap ids are assigned > dynamically and therefore so will the /dev/ionX designation. > From my understanding, security rules like selinux need to > be fully specified at boot time so I'm not sure how you would > be able to write rules to differentiate between /dev/ionX and > /dev/ionY without knowing the values at boottime. Isn't this something that should be managable via udev rules that ensure stable names in the same way as for things like disks or ethernet controllers (even if it just ends up doing something like /dev/ion-gpu or whatever)? If we're not giving it enough information to assign stable names where needed we probably need to fix that anyway.
Attachment:
signature.asc
Description: PGP signature