Re: Normal user can ask status of services

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Op za 26 aug 2023 om 15:16 schreef Andrei Borzenkov <arvidjaar@xxxxxxxxx>:
Do not send personal reply to the list post.

On 26.08.2023 15:35, Cecil Westerhof wrote:
> Op za 26 aug 2023 om 13:45 schreef Andrei Borzenkov <arvidjaar@xxxxxxxxx>:
>
>> On 26.08.2023 10:44, Cecil Westerhof wrote:
>>>
>>> Is this the expected behaviour?
>>
>> Yes, it is.
>>
>
> It seemed strange to me, but I will not worry then.
> Thanks.
>
> At the moment it is not important, but if I do not want that a normal user
> can query the status: can I circumvent this?
>

I am not sure. systemctl just calls
org.freedesktop.DBus.Properties.GetAll on unit D-Bus path. I am not
aware of any way to restrict it in systemd. You may restrict it on the
D-Bus level. Currently it is open to all

                 <allow send_destination="org.freedesktop.systemd1"
                        send_interface="org.freedesktop.DBus.Properties"
                        send_member="GetAll"/>

I do not know if it is possible to put restrictions only on some paths.

Thanks, I will look into it.

--
Cecil Westerhof

[Index of Archives]     [LARTC]     [Bugtraq]     [Yosemite Forum]     [Photo]

  Powered by Linux