xdg-app without setuid



I just pushed some changes to make xdg-app use user namespaces, which
means it does not require any elevated permissions like setuid or
setcap.

I need to do some more testing on it to make sure nothing broke, but it
seems to work for me.

However, there is an issue with some 4.0.x kernels, where it causes a
panic. For fedora this is fixed in the 4.0.4-302 kernel (and it works
with previous 3.19 kernels). If you want to test this, make sure you
have a new enough or old enough kernel.


[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]