[systemd-devel] RFC: Passing on initial client user in systemd-userdbd

Dominik George nik at naturalnet.de
Tue Nov 29 13:57:25 UTC 2022


Hi,

> Just add the capability to the service unit file.

Sure, I can do that.

My doubts are not about how to do it, but whether it is a good idea. CAP_SYS_ADMIN is a rather huge pile of capabilities, and certainly there is a reason userdbd runs with a very constrained set now?

-nik
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.freedesktop.org/archives/systemd-devel/attachments/20221129/b2ff6c60/attachment.htm>


More information about the systemd-devel mailing list