Uploaded image for project: ' AGL Development'
  1. AGL Development
  2. SPEC-4579

Run applaunchd under a separate user

XMLWordPrintable

      Since applaunchd needs to start/stop systemd units, the user is granted elevated systemd unit-management permissions via PolKit policy. If applaunchd and all the apps run under the same agl-driver user, all the apps have these elevated systemd permissions too. Separating them into different users allows removing elevated systemd unit-management permission from individual apps, but leaving such permission for applaunchd, which enhances overall security of the system.

       

        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

            denix Denys Dmytriyenko
            denix Denys Dmytriyenko
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: