Re: dmesg restricted to root in Rawhide

2024-03-06 Thread Zbigniew Jędrzejewski-Szmek
On Mon, Mar 04, 2024 at 11:37:49PM -0700, Chris Murphy wrote: > > > On Wed, Feb 28, 2024, at 6:45 AM, Peter Robinson wrote: > > On Wed, 28 Feb 2024 at 13:38, Barry Scott wrote: > >> > >> > >> > >> On 28 Feb 2024, at 10:24, Karel Zak wrote: > >> > >> You can restore the original behavior by

Re: dmesg restricted to root in Rawhide

2024-03-04 Thread Chris Murphy
On Wed, Feb 28, 2024, at 6:45 AM, Peter Robinson wrote: > On Wed, 28 Feb 2024 at 13:38, Barry Scott wrote: >> >> >> >> On 28 Feb 2024, at 10:24, Karel Zak wrote: >> >> You can restore the original behavior by using: >> >># sysctl kernel.dmesg_restrict=0 >> >> However, be aware of the

Re: dmesg restricted to root in Rawhide

2024-02-28 Thread Peter Robinson
On Wed, 28 Feb 2024 at 13:38, Barry Scott wrote: > > > > On 28 Feb 2024, at 10:24, Karel Zak wrote: > > You can restore the original behavior by using: > ># sysctl kernel.dmesg_restrict=0 > > However, be aware of the security consequences ;-) > > > Given I can get the same information from

Re: dmesg restricted to root in Rawhide

2024-02-28 Thread Barry Scott
> On 28 Feb 2024, at 10:24, Karel Zak wrote: > > You can restore the original behavior by using: > ># sysctl kernel.dmesg_restrict=0 > > However, be aware of the security consequences ;-) Given I can get the same information from journalctl -k what is the improvement? Barry --

Re: dmesg restricted to root in Rawhide

2024-02-28 Thread Daniel P . Berrangé
On Wed, Feb 28, 2024 at 10:30:10AM +, Richard W.M. Jones wrote: > On Wed, Feb 28, 2024 at 11:24:41AM +0100, Karel Zak wrote: > > On Tue, Feb 27, 2024 at 08:15:49PM +, Richard W.M. Jones wrote: > > > > > >

Re: dmesg restricted to root in Rawhide

2024-02-28 Thread Richard W.M. Jones
On Wed, Feb 28, 2024 at 11:24:41AM +0100, Karel Zak wrote: > On Tue, Feb 27, 2024 at 08:15:49PM +, Richard W.M. Jones wrote: > > > > https://gitlab.com/cki-project/kernel-ark/-/commit/ed5ba266c61e01a52359b5793a627e7c9aae8854 > > > > Why wasn't this a Fedora change proposal? > > > > Also the

Re: dmesg restricted to root in Rawhide

2024-02-28 Thread Karel Zak
On Tue, Feb 27, 2024 at 08:15:49PM +, Richard W.M. Jones wrote: > > https://gitlab.com/cki-project/kernel-ark/-/commit/ed5ba266c61e01a52359b5793a627e7c9aae8854 > > Why wasn't this a Fedora change proposal? > > Also the justification given for such a major change is very thin. > I'm sure

Re: dmesg restricted to root in Rawhide

2024-02-28 Thread Tom Hughes via devel
On 28/02/2024 10:05, Marcin Juszkiewicz wrote: W dniu 27.02.2024 o 22:27, Justin Forbes pisze: In practice, this isn't that much of a lockdown for most fedora users. We give the default user on a system wheel access which means both 'sudo dmesg' and 'journalctl -k' work as is. You wish... $ 

Re: dmesg restricted to root in Rawhide

2024-02-28 Thread Marcin Juszkiewicz
W dniu 27.02.2024 o 22:27, Justin Forbes pisze: In practice, this isn't that much of a lockdown for most fedora users. We give the default user on a system wheel access which means both 'sudo dmesg' and 'journalctl -k' work as is. You wish... $ id uid=1003(marcin) gid=1006(marcin)

Re: dmesg restricted to root in Rawhide

2024-02-28 Thread Daniel P . Berrangé
On Tue, Feb 27, 2024 at 08:15:49PM +, Richard W.M. Jones wrote: > > https://gitlab.com/cki-project/kernel-ark/-/commit/ed5ba266c61e01a52359b5793a627e7c9aae8854 > > Why wasn't this a Fedora change proposal? > > Also the justification given for such a major change is very thin. > I'm sure

Re: dmesg restricted to root in Rawhide

2024-02-27 Thread Justin Forbes
On Tue, Feb 27, 2024 at 2:16 PM Richard W.M. Jones wrote: > > > https://gitlab.com/cki-project/kernel-ark/-/commit/ed5ba266c61e01a52359b5793a627e7c9aae8854 > > Why wasn't this a Fedora change proposal? > > Also the justification given for such a major change is very thin. > I'm sure product

Re: dmesg restricted to root in Rawhide

2024-02-27 Thread Chris Adams
Once upon a time, Richard W.M. Jones said: > https://gitlab.com/cki-project/kernel-ark/-/commit/ed5ba266c61e01a52359b5793a627e7c9aae8854 > > Why wasn't this a Fedora change proposal? > > Also the justification given for such a major change is very thin. > I'm sure product security can give us

dmesg restricted to root in Rawhide

2024-02-27 Thread Richard W.M. Jones
https://gitlab.com/cki-project/kernel-ark/-/commit/ed5ba266c61e01a52359b5793a627e7c9aae8854 Why wasn't this a Fedora change proposal? Also the justification given for such a major change is very thin. I'm sure product security can give us some more details of precisely what exploits will be