Gentoo Archives: gentoo-hardened

From: "Anthony G. Basile" <basile@××××××××××××××.edu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] xattr/acl/cap
Date: Mon, 21 May 2012 18:02:17
Message-Id: 4FBA6E93.7090807@opensource.dyc.edu
In Reply to: Re: [gentoo-hardened] xattr/acl/cap by Maxim Kammerer
1 On 05/20/2012 08:06 PM, Maxim Kammerer wrote:
2 > On Mon, May 21, 2012 at 1:46 AM, Anthony G. Basile
3 > <basile@××××××××××××××.edu> wrote:
4 >> Okay this is where I have to redirect you because I'm not aware of this
5 >> particular issue, ie why consolekit needs tmpfs posix acls.
6 >
7 > If I am not mistaken, ConsoleKit uses ACLs to grant the currently
8 > active user access to various /dev nodes. E.g., with ConsoleKit you
9 > don't need to put users into "video", "audio" and "cdrom" groups
10 > anymore (corresponding to v4l, sound, and dvd/cdrom devices), so
11 > access permissions are more fine-grained and based on need.
12 >
13
14 oh and since /dev is tmpfs, hence the need.
15
16 @original poster. turn this on, its a good thing :)
17
18 --
19 Anthony G. Basile, Ph. D.
20 Chair of Information Technology
21 D'Youville College
22 Buffalo, NY 14201
23 (716) 829-8197