Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
The rules in this file want to make sound, video and cdrom devices available to the locally logged in user by setting the device files to mode 0666, which in fact makes these available to all users. This is a privacy problem when applied to sound, input and video devices. However, this is unnecessary, as the access for the locally logged in user is already managed by udev and logind. The whole processes is more or less undocumented [1] Relevant rules files are /lib/udev/rules.d/70-uaccess.rules /lib/udev/rules.d/71-seat.rules /lib/udev/rules.d/83-seat-late.rules In the end, either the udev uaccess build [2] or logind [3] set a acl to the relevant device files so that the local user can access it. Remove the local rule file. [1] https://github.com/systemd/systemd/issues/4288 [2] https://github.com/systemd/systemd/blob/4d484e14bb9864cef1d124885e625f33bf31e91c/src/udev/udev-builtin-uaccess.c#L51 [3] https://github.com/systemd/systemd/blob/4d484e14bb9864cef1d124885e625f33bf31e91c/src/login/logind-seat.c#L216
- Loading branch information