[systemd-devel] grant users access to certain services only

Mantas Mikulėnas grawity at gmail.com
Fri Aug 21 03:38:28 PDT 2015


On Fri, Aug 21, 2015 at 1:29 PM, Dominick Grift <dac.override at gmail.com>
wrote:

> On Fri, Aug 21, 2015 at 01:10:51PM +0300, Mantas Mikulėnas wrote:
> <snip>
>
> > >
> > > i think it kind of sucks that systemctl --user list-units can be used
> to
> > > determine who is currently logged in. ( it shows active mount units for
> > > XDG_RUNTIME_DIR and since those have UID as name you can see who is
> > > logged in.
> > >
> >
> > Hmm, and `findmnt` doesn't?
>
> unpriv users do not have access to mount or findmount in my system, and
> for example df -h does not list them because the user is not allowed to
> get attributes of tmpfs file systems. So /run/user mounts do not show up
> in df -h
>

Do they have access to `cat /proc/self/mounts`?

-- 
Mantas Mikulėnas <grawity at gmail.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.freedesktop.org/archives/systemd-devel/attachments/20150821/0bbae96e/attachment.html>


More information about the systemd-devel mailing list