From 44e7da6d5645f6b96de774bdb8b51f34cb531292 Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Wed, 12 Aug 2026 10:47:32 +0200 Subject: [PATCH] dbus: policy comment predates the per-sender uid lookup It still described treating every system-bus caller as unprivileged as the state of things, which stopped being true when Finit learned to ask the broker who sent a call. Signed-off-by: Joachim Wiberg --- dbus-1/org.finit.conf | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/dbus-1/org.finit.conf b/dbus-1/org.finit.conf index ea730e9b..5eb40fc2 100644 --- a/dbus-1/org.finit.conf +++ b/dbus-1/org.finit.conf @@ -11,10 +11,10 @@ every state-changing method at the broker. finit *also* enforces per-method authorisation itself (LINK_METHOD_PRIVILEGED), so defense-in-depth: even if a permissive policy is installed by - mistake, finit rejects unprivileged state changes via SO_PEERCRED - on the local bus and by treating every system-bus caller as - unprivileged (peer_uid = (uid_t)-1) until a per-sender uid lookup - via GetConnectionUnixUser is implemented. + mistake, finit rejects unprivileged state changes. It reads the + caller from SO_PEERCRED on the local bus, and on the system bus it + asks the broker who sent each privileged call, via + GetConnectionUnixUser. -->