Re: sysutils/upower: unveil to prevent execution

2023-11-08 Thread Klemens Nanni
On Wed, Nov 08, 2023 at 03:30:37PM +0100, Landry Breuil wrote: > Le Wed, Nov 08, 2023 at 02:20:22PM +, Klemens Nanni a écrit : > > On Wed, Nov 08, 2023 at 03:11:33PM +0100, Landry Breuil wrote: > > > Le Wed, Nov 08, 2023 at 02:56:53PM +0100, Landry Breuil a écrit : > > > > if you want to go dow

Re: sysutils/upower: unveil to prevent execution

2023-11-08 Thread Landry Breuil
Le Wed, Nov 08, 2023 at 02:20:22PM +, Klemens Nanni a écrit : > On Wed, Nov 08, 2023 at 03:11:33PM +0100, Landry Breuil wrote: > > Le Wed, Nov 08, 2023 at 02:56:53PM +0100, Landry Breuil a écrit : > > > if you want to go down that road, barring any glib madness about various > > > ~/.cache or .

Re: sysutils/upower: unveil to prevent execution

2023-11-08 Thread Klemens Nanni
On Wed, Nov 08, 2023 at 03:11:33PM +0100, Landry Breuil wrote: > Le Wed, Nov 08, 2023 at 02:56:53PM +0100, Landry Breuil a écrit : > > if you want to go down that road, barring any glib madness about various > > ~/.cache or .local stuff, upower itself should only need wc on > > /var/db/upower/ >

Re: sysutils/upower: unveil to prevent execution

2023-11-08 Thread Landry Breuil
Le Wed, Nov 08, 2023 at 02:56:53PM +0100, Landry Breuil a écrit : > Le Wed, Nov 08, 2023 at 01:49:56PM +, Klemens Nanni a écrit : > > Started by D-Bus, this upowerd(8) runs as root without the usual > > OpenBSD security considerations. > > > > upowerd(8) used to support scripts, but deprecated

Re: sysutils/upower: unveil to prevent execution

2023-11-08 Thread Landry Breuil
Le Wed, Nov 08, 2023 at 01:49:56PM +, Klemens Nanni a écrit : > Started by D-Bus, this upowerd(8) runs as root without the usual > OpenBSD security considerations. > > upowerd(8) used to support scripts, but deprecated them in 2013. > I don't see any other code that would fork or exec stuff. >

sysutils/upower: unveil to prevent execution

2023-11-08 Thread Klemens Nanni
Started by D-Bus, this upowerd(8) runs as root without the usual OpenBSD security considerations. upowerd(8) used to support scripts, but deprecated them in 2013. I don't see any other code that would fork or exec stuff. apm(4) ioctls is not covered by pledge(2), sensors readying via sysctl(2) sh