[PATCH] Hal privilige seperation

Artem Kachitchkine Artem.Kachitchkin at Sun.COM
Fri Jan 20 08:13:30 PST 2006


>   How does it work? Just before drops it's root privs. a small program is
>   startup which will remain running as root and does the real execution of the
>   addons/probes/callouts on hals behalf.

Does hald-runner exist only so that the addons have a privileged 
ancestor they can inherit privileged uid/gid from? If so, wouldn't it be 
much easier if hald regained its privileges temporarily before exec'ing 
an addon and dropping them immediately after?

Also, this assumes that all addons/probes/callouts must run as root. 
What if some of them don't?

-Artem.



More information about the hal mailing list