diff options
| author | Alois Wohlschlager <alois1@gmx-topmail.de> | 2022-08-07 19:12:37 +0200 |
|---|---|---|
| committer | Alois Wohlschlager <alois1@gmx-topmail.de> | 2022-08-07 19:12:37 +0200 |
| commit | f238a0a093462bbeea345235a3850a2e31794664 (patch) | |
| tree | dc2ce7dd8ae71cbec4fb417d3e1c544701c69741 /pkgs/development/python-modules/rangehttpserver | |
| parent | 01521f33f347b57dac8ea5dfa2aa83c531bfa8ea (diff) | |
kwin: don't leak CAP_SYS_NICE
The capability wrapper raises CAP_SYS_NICE into the ambient set. As a
result, not only is kwin_wayland itself granted that capability, but
also all applications started by it (even transitively, i.e. the entire
desktop environment). While CAP_SYS_NICE is not a particularly dangerous
capability, that behaviour is still not great; furthermore it's annoying
because it breaks programs checking that they are not granted any
capabilities (e.g. bubblewrap).
Fix this behaviour by adding a patch that causes kwin_wayland to lower
CAP_SYS_NICE from the ambient capability set at startup. That way,
expected upstream behaviour is restored.
Diffstat (limited to 'pkgs/development/python-modules/rangehttpserver')
0 files changed, 0 insertions, 0 deletions
