- Fix LICENSE - Use GROUPS - Add sample config file - Add pkg-message - Take maintainership
Details
- Reviewers
uqs bapt jbeich • hselasky - Commits
- rP446043: - Fix LICENSE
Diff Detail
- Lint
Lint Skipped - Unit
Tests Skipped
Event Timeline
Hi Baptiste,
Would you mind to add the u2f.conf to the port that you've already committed?
Thanks
security/libu2f-host/pkg-plist | ||
---|---|---|
2 | All your rules do is change permissions, shouldn't you be using devfs.rules for this instead of devd actions? |
security/libu2f-host/pkg-plist | ||
---|---|---|
2 | It was discussed with hselasky@ I want to hear bapt's opinion, because he has already committed this port. |
u2f.conf changes the permissions of the $cdev node of the ugen device so that the libu2f-host can access this devices on FreeBSD.
Please feel free to comment or propose changes.
Can you update diff against the existing port?
security/libu2f-host/files/u2f.conf.in | ||
---|---|---|
6 ↗ | (On Diff #30007) | Did you convert devd rules from udev via script? If so please add it under /usr/ports/Tools/scripts/ or create USES. |
8 ↗ | (On Diff #30007) | This grants r/w access for default group which is probably wheel unless overriden via /etc/devfs.rules. Maybe create a dedicated group (e.g. u2f) and document it somewhere (manpage or pkg-message). Here're a few examples:
|
security/libu2f-host/pkg-plist | ||
2 | Can you quote the discussion or post a link to the achived copy? |
sorry I have missed that review
if you want to grab the port and make it yours, feel free to grab it :)
I would prefer a devfs.rules but maybe the devd conf file is more userfriendly
security/libu2f-host/files/u2f.conf.in | ||
---|---|---|
8 ↗ | (On Diff #30007) | I agree |
Thanks Baptiste!
I hope that Hans will shed some light on the device permissions then I'll proceed to change the port accordingly.
It might be better if this library installed its own group which these devices are chowned to?
Regarding device permissions, please check if I forgot anything else.
Thanks for your quick reply, Hans
Looks good to me with regards to the USB bits and the devd script. I'm not sure if you should install u2f.conf directly or postfixed with .sample which will require user-interaction.
Well, I think that just installing u2f.conf would be enough. Maybe adding a note in pkg-message to remind consumers that they should restart devd?
Thanks again :)
Here is an example:
====================================================================== Note that a sample file is installed in %%PREFIX%%/etc/devd/u2f.conf to allow u2f access permissions. You should only restart devd with the command: # service devd restart ======================================================================
GIDs | ||
---|---|---|
172 | Maybe pick group-only free number e.g., 116, 141, 151. | |
UIDs | ||
177 | Maybe drop this, so GIDs can reserve group-only number. | |
security/libu2f-host/Makefile | ||
31 | Why do you need a separate user as well? Does the port install a daemon and/or rc.d script? | |
security/libu2f-host/files/pkg-message.in | ||
4 | "Note that" is redundant. | |
8 | You're forgetting the user has to be part of u2f group. Maybe rephrase the whole file e.g., The package requires read/write access to USB devices. To facilitate such access it comes with a devd.conf(5) file, but you still need to restart devd(8), add the desired users to "u2f" group and log those out of the current session. For example: $ pw group mod u2f -m <user> $ shutdown -r now For details, see %%PREFIX%%/etc/devd/u2f.conf | |
security/libu2f-host/pkg-plist | ||
11 | Can you alphabetically sort as if @sample was absent? See the output from make restage && make makeplist. |