1
Fork 0
mirror of https://github.com/RGBCube/serenity synced 2025-07-27 09:37:34 +00:00

Base: Make anon's helper services run with 600 socket permissions

Some of these were using 660 permissions which meant that other users
in the "users" group could connect to anon's service processes.

Let's tighten things up by not allowing that. :^)
This commit is contained in:
Andreas Kling 2021-06-06 18:03:57 +02:00
parent 4c47b3951d
commit b968d44375

View file

@ -1,6 +1,6 @@
[RequestServer] [RequestServer]
Socket=/tmp/portal/request Socket=/tmp/portal/request
SocketPermissions=660 SocketPermissions=600
Lazy=1 Lazy=1
Priority=low Priority=low
User=anon User=anon
@ -10,7 +10,7 @@ AcceptSocketConnections=1
[WebContent] [WebContent]
Socket=/tmp/portal/webcontent Socket=/tmp/portal/webcontent
SocketPermissions=660 SocketPermissions=600
Lazy=1 Lazy=1
User=anon User=anon
BootModes=graphical BootModes=graphical
@ -19,7 +19,7 @@ AcceptSocketConnections=1
[ImageDecoder] [ImageDecoder]
Socket=/tmp/portal/image Socket=/tmp/portal/image
SocketPermissions=660 SocketPermissions=600
Lazy=1 Lazy=1
User=anon User=anon
BootModes=graphical BootModes=graphical
@ -28,7 +28,7 @@ AcceptSocketConnections=1
[WebSocket] [WebSocket]
Socket=/tmp/portal/websocket Socket=/tmp/portal/websocket
SocketPermissions=660 SocketPermissions=600
Lazy=1 Lazy=1
Priority=low Priority=low
User=anon User=anon
@ -80,7 +80,7 @@ User=anon
[Clipboard] [Clipboard]
Socket=/tmp/portal/clipboard Socket=/tmp/portal/clipboard
SocketPermissions=660 SocketPermissions=600
Priority=low Priority=low
User=anon User=anon
@ -143,7 +143,7 @@ BootModes=text
[CppLanguageServer] [CppLanguageServer]
Socket=/tmp/portal/language/cpp Socket=/tmp/portal/language/cpp
SocketPermissions=660 SocketPermissions=600
Lazy=1 Lazy=1
User=anon User=anon
MultiInstance=1 MultiInstance=1
@ -151,7 +151,7 @@ AcceptSocketConnections=1
[ShellLanguageServer] [ShellLanguageServer]
Socket=/tmp/portal/language/shell Socket=/tmp/portal/language/shell
SocketPermissions=660 SocketPermissions=600
Lazy=1 Lazy=1
User=anon User=anon
MultiInstance=1 MultiInstance=1