Uploaded image for project: ' AGL Development'
  1. AGL Development
  2. SPEC-4579

Run applaunchd under a separate user


      Since applaunchd needs to start/stop systemd units, the user is granted elevated systemd unit-management permissions via PolKit policy. If applaunchd and all the apps run under the same agl-driver user, all the apps have these elevated systemd permissions too. Separating them into different users allows removing elevated systemd unit-management permission from individual apps, but leaving such permission for applaunchd, which enhances overall security of the system.


        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

            denix Denys Dmytriyenko
            denix Denys Dmytriyenko
            0 Vote for this issue
            2 Start watching this issue