The future of elogind/libelogind0

Thorsten Glaser t.glaser at tarent.de
Wed Oct 18 18:12:14 BST 2023


>On Wed, 18 Oct 2023, Mark Hindley wrote:
>
>>> There is xserver-xorg-legacy, is that not sufficient?
>>
>>Yes it is, but that runs the server as root with the obvious security
>>implications.
>
>Yeowch, it still doesn’t privdrop once no longer needed?

Uid:    1000    0       0       0
Gid:    1000    0       0       0

At least the real ugid are dropping; the effective, saved and fs ones
aren’t, so there :|

bye,
//mirabilos
-- 
Infrastrukturexperte • Qvest Digital AG
Am Dickobskreuz 10, D-53121 Bonn • https://www.qvest-digital.com/
Telephon +49 228 54881-393 • Fax: +49 228 54881-235
HRB AG Bonn 18196 • USt-ID (VAT): DE274355441
Vorstand: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg
Vorsitzender Aufsichtsrat: Peter Nöthen



More information about the Debian-init-diversity mailing list