@[email protected] to Open [email protected] • 8 months agosystemd Rolling Out "run0" As sudo Alternativewww.phoronix.comexternal-linkmessage-square29fedilinkarrow-up1135arrow-down14cross-posted to: [email protected]
arrow-up1131arrow-down1external-linksystemd Rolling Out "run0" As sudo Alternativewww.phoronix.com@[email protected] to Open [email protected] • 8 months agomessage-square29fedilinkcross-posted to: [email protected]
minus-square@kbotclinkEnglish6•8 months agoWhile it may be true that getting rid of SUID binary is ideal, widening systemd’s security surface area is much more concerning to me than the sudo binary.
minus-square@[email protected]linkfedilink8•edit-28 months agoThis has already been possible, the patch modifying run.c to be able to do this is not even 400 lines long and was mostly just exposing its feature in a different way. (the entire patch was <1.5k lines, with most being docs, tests and a bit of plumbing for the colored terminal)
While it may be true that getting rid of SUID binary is ideal, widening systemd’s security surface area is much more concerning to me than the sudo binary.
This has already been possible, the patch modifying
run.c
to be able to do this is not even 400 lines long and was mostly just exposing its feature in a different way. (the entire patch was <1.5k lines, with most being docs, tests and a bit of plumbing for the colored terminal)