pro_grammer@programming.dev to Open Source@lemmy.ml · 2 个月前systemd Rolling Out "run0" As sudo Alternativewww.phoronix.comexternal-linkmessage-square29fedilinkarrow-up1138arrow-down15cross-posted to: news@lemmy.linuxuserspace.show
arrow-up1133arrow-down1external-linksystemd Rolling Out "run0" As sudo Alternativewww.phoronix.compro_grammer@programming.dev to Open Source@lemmy.ml · 2 个月前message-square29fedilinkcross-posted to: news@lemmy.linuxuserspace.show
minus-squarealeph@lemm.eelinkfedilinkEnglisharrow-up3arrow-down2·edit-22 个月前So there would be no practical benefits of switching?
minus-squareTobias Hunger@programming.devlinkfedilinkarrow-up16·edit-22 个月前It gets rid of one more SUID binary. That’s always a win for security. Sudo probably is way more comfortable to use and has way more configurable, too – that usually does not help to make a tool secure either:-)
minus-squarekbotc@lemmy.worldlinkfedilinkEnglisharrow-up8arrow-down2·2 个月前While it may be true that getting rid of SUID binary is ideal, widening systemd’s security surface area is much more concerning to me than the sudo binary.
minus-squareNekkoDroid@programming.devlinkfedilinkarrow-up8·edit-22 个月前This has already been possible, the patch modifying run.c to be able to do this is not even 400 lines long and was mostly just exposing its feature in a different way. (the entire patch was <1.5k lines, with most being docs, tests and a bit of plumbing for the colored terminal)
So there would be no practical benefits of switching?
It gets rid of one more SUID binary. That’s always a win for security.
Sudo probably is way more comfortable to use and has way more configurable, too – that usually does not help to make a tool secure either:-)
While it may be true that getting rid of SUID binary is ideal, widening systemd’s security surface area is much more concerning to me than the sudo binary.
This has already been possible, the patch modifying
run.c
to be able to do this is not even 400 lines long and was mostly just exposing its feature in a different way. (the entire patch was <1.5k lines, with most being docs, tests and a bit of plumbing for the colored terminal)