Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] sys-apps/pcsc-lite needs to access /sys
Date: Mon, 17 Feb 2014 19:24:55
Message-Id: 20140217192451.GA3650@gentoo.org
In Reply to: Re: [gentoo-hardened] sys-apps/pcsc-lite needs to access /sys by Luis Ressel
1 On Sat, Feb 15, 2014 at 06:03:28PM +0100, Luis Ressel wrote:
2 > I've had a first look at this. Sadly, there's no gid mount option for
3 > sysfs. Another complication is that the group isn't granted any rights
4 > anyway.
5 >
6 > I'll examine what changes to the kernel would be neccessary. (For sure,
7 > one could also create an init script with chown/chmod, but that seems a
8 > bit messy.)
9
10 The init script approach is what most distributions are doing. We also
11 relabel cpu/online in the selinux_gentoo init script.
12
13 But the approach you mentioned on the other mailinglist (regarding reusing
14 the statement already in use for /proc stuff) seems like a valid case -
15 interesting to see what's going to happen ;)
16
17 Wkr,
18 Sven Vermeulen

Replies

Subject Author
Re: [gentoo-hardened] sys-apps/pcsc-lite needs to access /sys Luis Ressel <aranea@×××××.de>