On Mon, 6 Jan 2025, Rhialto wrote:
Yes, normally you would need to be in single user mode to remove the schg flag. This is not mentioned in chflags(1) but in secmodel_securelevel(9). But if you run X, you typically need to be in insecure mode anyway, so this point doesn't apply.
The "need to be at secure-level 0" is also mentioned in chflag(2) ... +---------------------+--------------------------+----------------------+ | Paul Goyette (.sig) | PGP Key fingerprint: | E-mail addresses: | | (Retired) | 1B11 1849 721C 56C8 F63A | paul%whooppee.com@localhost | | Software Developer | 6E2E 05FD 15CE 9F2D 5102 | pgoyette%netbsd.org@localhost | | & Network Engineer | | pgoyette99%gmail.com@localhost | +---------------------+--------------------------+----------------------+