Some privilege reduction patches

Martin Pitt martin at piware.de
Wed Feb 15 23:10:21 PST 2006


Hi!

Sjoerd Simons [2006-02-15 20:16 +0100]:
> I am currently leaning to configuring hal to never read from the kernel socket,
> but always from acpid. 

I agree, at least for Debian/Ubunu. However, it's certainly not a good
upstream default.

> > On the other side, we could
> > change the addon to only reconnect to eventsource which was successful
> > connected before.
> 
> That still has race conditions (at least in debian).. The normal upgrade
> process first stop's the daemons to be upgraded, does all the unpacking and
> stuff, then starts the daemons one by one. There is no guarantee that acpi is
> started before hal in this case.... 

It would be guaranteed if hal would have a dependency on acpid, but I
think this should be avoided.

Martin
-- 
Martin Pitt              http://www.piware.de
Ubuntu Developer   http://www.ubuntulinux.org
Debian Developer        http://www.debian.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://lists.freedesktop.org/archives/hal/attachments/20060216/f234d512/attachment.pgp


More information about the hal mailing list