Re: [systemd-devel] Device cgroups for user systemd scopes

2015-03-04 Thread Lennart Poettering
On Wed, 04.03.15 18:50, Alexander Larsson (al...@redhat.com) wrote: > The user instance of systemd does not seem to apply the DevicePolicy for > scopes. I.e. I can run: None of the controllers are currently available to unprivileged processes. This will be opened up as the kernel gets improved to

[systemd-devel] Device cgroups for user systemd scopes

2015-03-04 Thread Alexander Larsson
The user instance of systemd does not seem to apply the DevicePolicy for scopes. I.e. I can run: $ systemd-run --user --scope --property=DevicePolicy=strict glxgears Running as unit run-994.scope. ... runs fine, should fail to use DRI ... $ cat /run/user/1000/systemd/user/run-994.scope.d/50-Device