hidraw revoke ioctl queued for 6.12 🎉
with (pending) logind support this means we'll be able to hand hidraw fds to applications and revoke those on vt switch (or whenever we feel like, really).
=> More informations about this toot | More toots from whot@fosstodon.org
@whot is there any hope of a more general fd-revocation mechanism?
Flatpak has a “revokefs” FUSE filesystem so that updates can be pulled to a temporary directory by an unprivileged user, then access to that directory is revoked, so that once the checksums are verified the files can be hardlinked directly into the system repo without risk of the unprivileged user being able to modify the files after they are written.
=> More informations about this toot | More toots from wjt@mastodon.me.uk
@wjt tbh at least for me a general revoke() is very much in the "way too hard basket".
=> More informations about this toot | More toots from whot@fosstodon.org
@whot Fair enough!
=> More informations about this toot | More toots from wjt@mastodon.me.uk This content has been proxied by September (ba2dc).Proxy Information
text/gemini