On Thu, Dec 26, 2013 at 11:35 PM, Giovanni Campagna
<scampa.giova...@gmail.com> wrote:

> they do need the IPC_OWNER capability, to fake credentials
> on kdbus.

Oh, I guess we should just allow the owner/creator of the bus, the
user in this case, to do all that without the kernel capability.

We should not leak privileges into the user session, systemd --user
runs as the user and any other process of the same user can ptrace it.

Kay
_______________________________________________
systemd-devel mailing list
systemd-devel@lists.freedesktop.org
http://lists.freedesktop.org/mailman/listinfo/systemd-devel

Reply via email to