[systemd-devel] Udev rules for interfaces

2020-12-25 Thread Adi Ml
Hi, I am trying to generate rules in udev to block mass storage. It seems like it only checks the device itself (its class is 00), but not its interface classes (one of those is 08, a mass storage). It seems like there is only attr{bDeviceClass} but there is attr{bInterfaceClass} only when I speci

Re: [systemd-devel] Udev rules on reboot

2020-12-20 Thread Adi Ml
׳, 20 בדצמ׳ 2020, 15:59, מאת Mantas Mikulėnas ‏< graw...@gmail.com>: > On Sun, Dec 20, 2020 at 3:49 PM Lennart Poettering > wrote: > >> On Sa, 19.12.20 15:37, Adi Ml (maladi1...@gmail.com) wrote: >> >> > I see. so if I have a rule against a certain usb in udev,

Re: [systemd-devel] Udev rules on reboot

2020-12-19 Thread Adi Ml
I see. so if I have a rule against a certain usb in udev, it should be blocked automatically during the boot. בתאריך שבת, 19 בדצמ׳ 2020, 15:31, מאת Lennart Poettering ‏< lenn...@poettering.net>: > On Sa, 19.12.20 15:26, Adi Ml (maladi1...@gmail.com) wrote: > > > Hi, > &g

[systemd-devel] Udev rules on reboot

2020-12-19 Thread Adi Ml
Hi, Is there a way to enforce udev rules on all connected devices (which were connected pre-boot) after a reboot? I have tried udevadm trigger and seems like its not working Thank you ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org h

Re: [systemd-devel] Udev hardening

2020-12-14 Thread Adi Ml
בדצמ׳ 2020, 17:41, מאת Greg KH ‏< gre...@linuxfoundation.org>: > On Mon, Dec 14, 2020 at 05:31:17PM +0200, Adi Ml wrote: > > I am using udev in order to create a kiosk mode. I want to block devices > > which fit a certain vid pid. > > Block devices from where? The kernel

Re: [systemd-devel] Udev hardening

2020-12-14 Thread Adi Ml
calls in scripts- is it needed when the user can influence actions commited in the script ? בתאריך יום ב׳, 14 בדצמ׳ 2020, 16:45, מאת Greg KH ‏< gre...@linuxfoundation.org>: > On Mon, Dec 14, 2020 at 04:30:58PM +0200, Adi Ml wrote: > > Hi, > > Is there some way to detect whi

Re: [systemd-devel] Udev hardening

2020-12-14 Thread Adi Ml
בתאריך יום ב׳, 14 בדצמ׳ 2020, 15:40, מאת Greg KH ‏< gre...@linuxfoundation.org>: > On Mon, Dec 14, 2020 at 02:54:31PM +0200, Adi Ml wrote: > > Hi, > > > > I would like to harden my udev service with the > > SystemCallFilter option. What systemcalls should be

[systemd-devel] Udev hardening

2020-12-14 Thread Adi Ml
Hi, I would like to harden my udev service with the SystemCallFilter option. What systemcalls should be permitted/allowed in order to secure it and avoid irrelevant system calls? Thank you! ___ systemd-devel mailing list systemd-devel@lists.freedesktop.