[PATCH] Hal privilige seperation
Artem Kachitchkine
Artem.Kachitchkin at Sun.COM
Fri Jan 20 08:13:30 PST 2006
> How does it work? Just before drops it's root privs. a small program is
> startup which will remain running as root and does the real execution of the
> addons/probes/callouts on hals behalf.
Does hald-runner exist only so that the addons have a privileged
ancestor they can inherit privileged uid/gid from? If so, wouldn't it be
much easier if hald regained its privileges temporarily before exec'ing
an addon and dropping them immediately after?
Also, this assumes that all addons/probes/callouts must run as root.
What if some of them don't?
-Artem.
More information about the hal
mailing list