summaryrefslogtreecommitdiff
path: root/pkgs/development/python-modules/rangehttpserver
diff options
context:
space:
mode:
authorAlois Wohlschlager <alois1@gmx-topmail.de>2022-08-07 19:12:37 +0200
committerAlois Wohlschlager <alois1@gmx-topmail.de>2022-08-07 19:12:37 +0200
commitf238a0a093462bbeea345235a3850a2e31794664 (patch)
treedc2ce7dd8ae71cbec4fb417d3e1c544701c69741 /pkgs/development/python-modules/rangehttpserver
parent01521f33f347b57dac8ea5dfa2aa83c531bfa8ea (diff)
kwin: don't leak CAP_SYS_NICE
The capability wrapper raises CAP_SYS_NICE into the ambient set. As a result, not only is kwin_wayland itself granted that capability, but also all applications started by it (even transitively, i.e. the entire desktop environment). While CAP_SYS_NICE is not a particularly dangerous capability, that behaviour is still not great; furthermore it's annoying because it breaks programs checking that they are not granted any capabilities (e.g. bubblewrap). Fix this behaviour by adding a patch that causes kwin_wayland to lower CAP_SYS_NICE from the ambient capability set at startup. That way, expected upstream behaviour is restored.
Diffstat (limited to 'pkgs/development/python-modules/rangehttpserver')
0 files changed, 0 insertions, 0 deletions