The kdbuswreck
The kdbuswreck
Posted Apr 23, 2015 8:41 UTC (Thu) by smurf (subscriber, #17840)In reply to: The kdbuswreck by ncm
Parent article: The kdbuswreck
kdbus doesn't add anything to the way systemd handles capabilities, except remove the race condition inherent in checking for them. Passing them through kdbus also doesn't add any and privacy concerns because quite frankly, the knowledge whether or not a particular process does or does not have a particular capability is not a security hole; call me somewhat dumb but offhand I can't think of a way to make it into one.
Rejecting kdbus just because it uses caps is thus somewhat disingenious.
Posted Apr 23, 2015 22:31 UTC (Thu)
by luto (guest, #39314)
[Link]
The kdbuswreck