[PATCH] restrict D-Bus interface to root only

Dan Williams dcbw
Thu Dec 27 00:48:13 PST 2007


By default; distros can do what they want.  As a bonus, this removes a
SUSE/Fedora-ism (debian uses group permissions instead).


diff -up wpa_supplicant-0.5.7/dbus-wpa_supplicant.conf.permfix wpa_supplicant-0.5.7/dbus-wpa_supplicant.conf
--- wpa_supplicant-0.5.7/dbus-wpa_supplicant.conf.permfix	2007-10-20 07:42:01.000000000 -0400
+++ wpa_supplicant-0.5.7/dbus-wpa_supplicant.conf	2007-10-20 07:42:22.000000000 -0400
@@ -8,10 +8,6 @@
                 <allow send_destination="fi.epitest.hostap.WPASupplicant"/>
                 <allow send_interface="fi.epitest.hostap.WPASupplicant"/>
         </policy>
-        <policy at_console="true">
-                <allow send_destination="fi.epitest.hostap.WPASupplicant"/>
-                <allow send_interface="fi.epitest.hostap.WPASupplicant"/>
-        </policy>
         <policy context="default">
                 <deny own="fi.epitest.hostap.WPASupplicant"/>
                 <deny send_destination="fi.epitest.hostap.WPASupplicant"/>





More information about the Hostap mailing list