Re: Security of confined user/application and access to video group

2017-06-07 Thread Germano Massullo
Il 07/06/2017 09:22, Lennart Poettering ha scritto: > On Tue, 06.06.17 17:44, Germano Massullo (germano.massu...@gmail.com) wrote: > >> 2017-06-06 14:40 GMT+02:00 Lennart Poettering : >>> Note sure what "boinc-client" does, but if this isn't turstworthy then >>> it probably

Re: Security of confined user/application and access to video group

2017-06-07 Thread Lennart Poettering
On Tue, 06.06.17 17:44, Germano Massullo (germano.massu...@gmail.com) wrote: > 2017-06-06 14:40 GMT+02:00 Lennart Poettering : > > Note sure what "boinc-client" does, but if this isn't turstworthy then > > it probably shouldn't be able to get access to "video". > >

Re: Security of confined user/application and access to video group

2017-06-06 Thread Germano Massullo
2017-06-06 14:40 GMT+02:00 Lennart Poettering : > Note sure what "boinc-client" does, but if this isn't turstworthy then > it probably shouldn't be able to get access to "video". boinc-client is the client side version of BOINC (Berkeley Open Infrastructure for Network

Re: Security of confined user/application and access to video group

2017-06-06 Thread Lennart Poettering
On Tue, 06.06.17 11:48, Germano Massullo (germano.massu...@gmail.com) wrote: > Hi there, I am the co-maintainer of boinc-client [1]. > boinc-client runs as a service, and both it and its working units run as > 'boinc' user and they are confined by SELinux. > Recently, I investigated to figure out

Re: Security of confined user/application and access to video group

2017-06-06 Thread Germano Massullo
Ah, forget the line Environment=LD_LIBRARY_PATH=/opt/amdgpu-pro/lib64 since it is needed only for my system ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org

Security of confined user/application and access to video group

2017-06-06 Thread Germano Massullo
Hi there, I am the co-maintainer of boinc-client [1]. boinc-client runs as a service, and both it and its working units run as 'boinc' user and they are confined by SELinux. Recently, I investigated to figure out why boinc-client, while running as a service, could not detect videocard for GPU