Gentoo Archives: gentoo-user

From: Peter Humphrey <peter@××××××××××××.uk>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] BOINC on a hardened system?
Date: Fri, 28 Jul 2017 21:59:32
Message-Id: 4060974.PtNcxUhcah@peak
In Reply to: Re: [gentoo-user] BOINC on a hardened system? by Gregory Woodbury
1 On Friday 28 Jul 2017 15:23:05 Gregory Woodbury wrote:
2 > By default, BOINC daemon is started by root and supposedly drops
3 > permissions after a bit. However, the CERNVM VirtualBox application
4 > cannot run as root, so they recommend running BOINC from a user
5 > account that has virtualbox permissions; VirtualBox, on the other
6 > hand, will not run as root for security reasons.
7 >
8 > I got around this by making BOINC as "user" and moving its $HOME to
9 > /home/boinc/ and I don't think I had to change anything (except the
10 > /etc/conf.d/boinc file.)
11
12 I run it as me in its own partition, under /home/prh/boinc/. I also had to
13 change /usr/share/applications/boincmgr.desktop so that I could run the GUI.
14
15 > I am not using any hardening in the kernel, so that may complicate things.
16
17 It does. Everything worked just fine until I hardened the kernel. I don't
18 know yet whether BOINC can run at all on a hardened system. Whence my
19 question.
20
21 > I currently run some 11 projects, including SETI, CERN, Einstein, and
22 > World Community Grid. Everything works fine for me.
23
24 Yes, I run seven projects, including all those except WCG.
25
26 --
27 Regards
28 Peter