[systemd-devel] [PATCH] Smack enabled systems need /dev special devices correctly labeled

Kay Sievers kay at vrfy.org
Mon Oct 14 16:10:51 PDT 2013


On Tue, Oct 15, 2013 at 12:59 AM, Michael Demeter
<michael.demeter at intel.com> wrote:
> Yes is is very specific to Smack.

Sure.

> Yes this has been tested here.

It looks to me like *everything* will have that label now. This is an
unconditional rule.

> It is not included as a policy file when the image is built if Smack is not
> enabled.. So will not affect anyone not using smack.

That's not the point, the point is is if *belongs* into the systemd
repo, not if it's *enabled* by default or not. From what I see, it's
nothing really we should ship upstream.

Also, it should not repeat the primary permissions settings from the
default rules, that is just not right.

Kay


More information about the systemd-devel mailing list