crosvm: stop inheriting extra groups in wayland device |
|||
Issue descriptionThe wayland virtio device should not have supplementary groups like daemon-store.
,
May 9 2018
,
May 14 2018
,
Jun 12 2018
After a few hours of collaborative investigation, the root of this issue is minijail, which should have dropped the supplementary gids (because crosvm never calls minijail_keep_supplementary_gids), but the call crosm does make to minijail_namespace_user_disable_setgroups sets a flag that prevents minijail from dropping the needed permissions with setgroups. The fix should probably be to have minijal call setgroups after entering the user namespace, but before disallowing setgroups permanently. |
|||
►
Sign in to add a comment |
|||
Comment 1 by tbuck...@chromium.org
, Feb 13 2018