Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <sven.vermeulen@××××××.be>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] sys-apps/pcsc-lite needs to access /sys
Date: Sun, 09 Feb 2014 12:43:33
Message-Id: CAPzO=NyqSGB4xYguH58ugfC1iFE+9tP74+08JkZRnHmu=95Jnw@mail.gmail.com
In Reply to: [gentoo-hardened] sys-apps/pcsc-lite needs to access /sys by Luis Ressel
1 Isn't there any mount option that you can pass so that all members of
2 a certain group can still access sysfs? Perhaps "gid="?
3
4 Wkr,
5 Sven Vermeulen
6
7 On Sun, Feb 9, 2014 at 1:35 PM, Luis Ressel <aranea@×××××.de> wrote:
8 > Hello,
9 >
10 >
11 > I'm currently experimenting with OpenPGP smartcards. For those, I
12 > need sys-apps/pcsc-lite, which features a daemon (pcscd). This daemon
13 > has its own user and doesn't run with root permissions. However, it
14 > needs to access some files in /sys which are only accessible by root
15 > due to GRKERNSEC_SYSFS_RESTRICT.
16 >
17 > I went with the following solution:
18 > chown root:pcscd /usr/sbin/pcscd
19 > chmod 0710 /usr/sbin/pcscd
20 > filecap /usr/sbin/pcscd dac_read_search
21 >
22 > Should I just propose the maintainer to add this to the ebuild
23 > (conditional on a "hardened" USE flag), or would another course of
24 > action be preferred?
25 >
26 >
27 > Regards,
28 > Luis Ressel
29 >
30 >
31 > --
32 > Luis Ressel <aranea@×××××.de>
33 > GPG fpr: F08D 2AF6 655E 25DE 52BC E53D 08F5 7F90 3029 B5BD

Replies

Subject Author
Re: [gentoo-hardened] sys-apps/pcsc-lite needs to access /sys Luis Ressel <aranea@×××××.de>