diff options
| author | Furkan Sahin <furkan-dev@proton.me> | 2018-06-13 00:39:24 +0200 |
|---|---|---|
| committer | Furkan Sahin <furkan-dev@proton.me> | 2018-06-13 00:39:24 +0200 |
| commit | 10b79007d3692ce9e2e128e8095c2f9e249bfb93 (patch) | |
| tree | 3317961dd1425f428ccdebce378e0f010d57a14b /include | |
| parent | 0b73ae587afdc9930b271b3d18aeb7d94ffcb3c3 (diff) | |
Perform (partial) server initialization before dropping privileges.
Some operations during backend creation (e.g. becoming DRM master)
require CAP_SYS_ADMIN privileges. At this point, sway has dropped them
already, though. This patch splits the privileged part of server_init
into its own function and calls it before dropping its privileges.
This fixes the bug with minimal security implications.
Diffstat (limited to 'include')
| -rw-r--r-- | include/sway/server.h | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/include/sway/server.h b/include/sway/server.h index 65d96e7a..963d4dc1 100644 --- a/include/sway/server.h +++ b/include/sway/server.h @@ -47,6 +47,8 @@ struct sway_server { struct sway_server server; +/* Prepares an unprivileged server_init by performing all privileged operations in advance */ +bool server_privileged_prepare(struct sway_server *server); bool server_init(struct sway_server *server); void server_fini(struct sway_server *server); void server_run(struct sway_server *server); |
