mirror of https://github.com/cutefishos/appmotor
[booster] Always drop extra groups for non-privileged apps. Fixes JB#49088
Don't trust to UID/GID received from untrusted invoker request when deciding whether to drop extra groups for non-privileged apps. The application's rights should depend only on the stated application's privileges and not on the caller's process rights. Drop setuid() because the boosters are launched under "nemo" user ID in user session. Signed-off-by: Igor Zhbanov <i.zhbanov@omprussia.ru>pull/1/head
parent
f84e8e15e0
commit
294cd4d37c
Loading…
Reference in New Issue